CVE-2026-35546
9.8Anviz · CX2 Lite and CX7 Firmware
Anviz CX2 Lite and CX7 devices are vulnerable to unauthenticated firmware uploads, allowing remote attackers to execute arbitrary code and obtain a reverse shell.
Executive summary
This critical vulnerability in Anviz CX2 Lite and CX7 firmware allows unauthenticated remote attackers to execute arbitrary code, posing a severe risk of full system compromise.
Vulnerability
This is an unauthenticated arbitrary code execution vulnerability (CWE-306) resulting from a lack of proper validation during the firmware upload process. An attacker can submit crafted archives to the device, which are then executed, granting the attacker a reverse shell on the underlying system.
Business impact
With a CVSS score of 9.8, this vulnerability represents an extreme risk to organizational infrastructure. Successful exploitation allows an attacker to gain complete control over the affected hardware, potentially leading to unauthorized network access, data exfiltration, or the use of these devices as pivots for lateral movement within the production environment.
Remediation
Immediate Action: Contact Anviz support or consult the vendor advisory (ICSA-26-106-03) to obtain the latest firmware updates. If no patch is available, isolate affected devices from public-facing networks immediately.
Proactive Monitoring: Monitor network traffic for unusual outbound connections, specifically those indicating reverse shell activity (e.g., unexpected SSH or netcat traffic).
Compensating Controls: Implement strict network segmentation to ensure these devices cannot be accessed by untrusted users and utilize a WAF or firewall rules to restrict access to the device management interfaces.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the critical nature of this vulnerability and the potential for full system compromise, organizations should prioritize the identification of all Anviz CX2 Lite and CX7 devices within their environment. Apply the necessary firmware updates immediately upon release by the vendor to close this critical security gap.