CVE-2026-35546

· NIST NVD ↗

Anviz CX2 Lite and CX7 are vulnerable to unauthenticated firmware uploads. This causes crafted archives to be accepted, enabling attackers to plant and execute code and obtain a reverse shell.

CRITICAL
CVSS severity
9.8
CVSS base score
2026-04-17
Published

CWE codes

CWE-306

Affected products

anviz:cx7_firmwareanviz:cx7anviz:cx2_lite_firmwareanviz:cx2_lite

Sources