Anviz CX2 Lite and CX7 Unauthenticated Remote Code Execution Vulnerability

Vulnerability

A vulnerability exists in Anviz CX2 Lite and CX7 devices, allowing unverified update packages to be uploaded. The devices unpack and execute a script from these packages, leading to unauthenticated remote code execution.

Impact

Exploitation of this vulnerability could result in unauthorized remote code execution on the affected devices.

Remediation

Anviz did not respond to CISA's attempts to coordinate these vulnerabilities. Users should contact Anviz for more information through their official contact page.

Added: Apr 17, 2026, 8:22 PM
Updated: Apr 17, 2026, 8:22 PM

Vulnerability Rating

Custom Algorithm
spread
2.4
impact
7.5
exploitability
4.7
remediation
7.9
relevance
6.1
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.