ZeroHour

CVE-2026-40461

CVSS 3.1
7.5 high
EPSS
<1%p21
Published
()
Modified
Description

Anviz CX2 Lite and CX7 are vulnerable to unauthenticated POST requests that modify debug settings (e.g., enabling SSH), allowing unauthorized state changes that can facilitate later compromise.

Vendors
anviz
Products
cx7 firmware, cx2 lite firmware
Weakness
CWE-306
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.