Anviz CX2 Lite and CX7 Unauthenticated Debug Settings Modification Vulnerability

Vulnerability

A vulnerability exists in Anviz CX2 Lite and CX7 products, allowing unauthenticated POST requests to alter debug settings, such as enabling SSH. This unauthorized modification can lead to subsequent compromises of the affected devices.

Impact

Exploitation of this vulnerability could result in unauthorized changes to device configurations, potentially allowing for later exploitation or compromise of the device.

Remediation

Anviz did not respond to CISA's attempts to coordinate these vulnerabilities. Users should contact Anviz for more information through their official contact page.

Added: Apr 17, 2026, 8:20 PM
Updated: Apr 17, 2026, 8:20 PM

Vulnerability Rating

Custom Algorithm
spread
2.4
impact
2.5
exploitability
4.7
remediation
7.9
relevance
6.1
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.