CVE-2026-40066
8.8Anviz · CX2 Lite and CX7
Anviz CX2 Lite and CX7 devices are vulnerable to unverified firmware update packages, which allow an attacker to achieve unauthenticated remote code execution.
Executive summary
A critical vulnerability in Anviz CX2 Lite and CX7 firmware allows unauthenticated remote code execution through the upload of malicious update packages.
Vulnerability
This flaw stems from a lack of verification for firmware update packages (CWE-494), enabling an attacker to trigger the execution of arbitrary scripts on the device. Despite the CVSS vector suggesting low privileges, the authoritative description confirms this is an unauthenticated remote code execution vulnerability.
Business impact
The ability for an unauthenticated attacker to execute arbitrary code on these devices represents a severe security risk, potentially leading to full device compromise and loss of confidentiality, integrity, and availability. With a CVSS score of 8.8, this vulnerability carries a high risk of lateral movement into the wider network environment.
Remediation
Immediate Action: Contact the vendor immediately via their official support channels to inquire about firmware updates, as a formal patch version is currently unknown.
Proactive Monitoring: Monitor network traffic for unusual outbound connections originating from the biometric devices and review device logs for unauthorized firmware upload attempts.
Compensating Controls: Isolate affected devices on a restricted management VLAN and use firewall rules to prevent unauthorized hosts from accessing the management interface of the devices.
Exploitation status
Public Exploit Available: No confirmed public exploit available.
Analyst recommendation
Given the potential for complete device compromise, organizations using Anviz CX2 Lite and CX7 hardware should prioritize the isolation of these devices from public-facing network segments. Administrators must actively engage with the vendor for remediation guidance and remain vigilant for any anomalous behavior until an official firmware update is available and applied.
More Anviz CVEs
Sources
Originally found and disclosed by An anonymous researcher reported this vulnerability to CISA., per the CVE Program record.