CVE-2026-35682
8.8Anviz · CX2 Lite
The Anviz CX2 Lite firmware contains a command injection vulnerability in the filename parameter, allowing authenticated attackers to execute arbitrary commands with root privileges.
Executive summary
A critical command injection vulnerability in the Anviz CX2 Lite firmware allows authenticated attackers to gain full root-level control over the affected device.
Vulnerability
The vulnerability is a command injection flaw (CWE-77) triggered via the filename parameter. It requires an authenticated user to successfully execute arbitrary commands, which leads to full root-level system access.
Business impact
Successful exploitation of this vulnerability grants an attacker complete control over the affected hardware at the highest privilege level. This poses a severe risk of data exfiltration, device manipulation, or the use of the compromised unit as a persistent foothold within the internal network. Given the CVSS score of 8.8, the potential for total system compromise necessitates immediate attention to prevent unauthorized lateral movement.
Remediation
Immediate Action: Contact Anviz support immediately to determine if a firmware update has been released, as no public patch is currently confirmed.
Proactive Monitoring: Monitor network traffic for unusual outbound connections from the CX2 Lite device and review authentication logs for suspicious administrative activity or unusual filename parameters.
Compensating Controls: Restrict access to the device management interface to trusted administrative IP addresses only, and isolate the device on a segmented network to limit potential impact.
Exploitation status
Public Exploit Available: No — there is no confirmed public exploit in the available data.
Analyst recommendation
Given the severity of root-level command execution, administrators must prioritize securing the management interface of all Anviz CX2 Lite units. Until a vendor-supplied patch is confirmed and applied, maintain strict access controls and network segmentation to mitigate the risk of unauthorized command execution by malicious actors.