ZeroHour

CVE-2026-35546

CVSS 3.1
9.8 critical
EPSS
<1%p46
Published
()
Modified
Description

Anviz CX2 Lite and CX7 are vulnerable to unauthenticated firmware uploads. This causes crafted archives to be accepted, enabling attackers to plant and execute code and obtain a reverse shell.

Vendors
anviz
Products
cx7 firmware, cx2 lite firmware
Weakness
CWE-306
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.