← Back to CVE search

CVE-2026-35546

Anviz CX2 Lite

Description

Anviz CX2 Lite and CX7 are vulnerable to unauthenticated firmware uploads. This causes crafted archives to be accepted, enabling attackers to plant and execute code and obtain a reverse shell.

CVSS 9.8EPSS 0.587%Risk 1.03
View source
Published
2026-04-17 20:16:35
Affected versions
unknown
Type
Core software
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H