CVE-2026-31927

· NIST NVD ↗

Anviz CX7 Firmware is vulnerable to an authenticated CSV upload which allows path traversal to overwrite arbitrary files (e.g., /etc/shadow), enabling unauthorized SSH access when combined with debug‑setting changes

MEDIUM
CVSS severity
4.9
CVSS base score
2026-04-17
Published

CWE codes

CWE-23

Affected products

anviz:cx7_firmwareanviz:cx7

Sources