Anviz CrossChex Standard
cpe:2.3:a:anviz:crosschex:*:*:*:*:*:*:*
- <= 0
A vulnerability exists in Anviz CX2 Lite and CX7 devices, allowing unverified update packages to be uploaded. The devices unpack and execute a script from these packages, leading to unauthenticated remote code execution.
Exploitation of this vulnerability could result in unauthorized remote code execution on the affected devices.
Anviz did not respond to CISA's attempts to coordinate these vulnerabilities. Users should contact Anviz for more information through their official contact page.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.