Anviz CrossChex Standard
cpe:2.3:a:anviz:crosschex:*:*:*:*:*:*:*
- <= 0
A command injection vulnerability has been identified in the Anviz CX2 Lite firmware, all versions. This vulnerability allows authenticated users to execute arbitrary commands by manipulating a filename parameter. Exploitation of this issue could lead to unauthorized root-level access on the device.
Exploitation of this vulnerability could result in authenticated command injection, allowing for arbitrary command execution with root privileges on the affected device.
Anviz did not respond to CISA's attempts to coordinate these vulnerabilities. Users should contact Anviz for more information through their official contact page.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.