CVE-2026-40461
7.5Anviz · CX2 Lite and CX7
Anviz CX2 Lite and CX7 devices are susceptible to unauthenticated POST requests that allow unauthorized modification of debug settings, such as enabling SSH.
Executive summary
A critical authentication bypass vulnerability in Anviz CX2 Lite and CX7 devices allows unauthenticated attackers to modify system debug settings, potentially facilitating deeper device compromise.
Vulnerability
This vulnerability is an authentication bypass (CWE-306) where an unauthenticated attacker can send crafted POST requests to the device. This action allows the modification of debug settings, specifically enabling services like SSH that should be restricted.
Business impact
The ability for an unauthenticated user to alter device configuration poses a severe risk to operational security. By enabling SSH, an attacker can gain persistent, unauthorized access to the underlying operating system, which may lead to total device control, data exfiltration, or the use of these devices as entry points into the broader internal network. With a CVSS score of 7.5, this high severity flaw warrants immediate attention to prevent unauthorized administrative control.
Remediation
Immediate Action: Contact Anviz support or monitor the official CISA ICS advisory page (ICSA-26-106-03) for the release of patched firmware, as no fix is currently available.
Proactive Monitoring: Inspect network traffic for unauthorized POST requests directed at these devices and audit logs for unexpected SSH service activation or configuration changes.
Compensating Controls: Isolate affected devices on a restricted management VLAN and implement strict firewall rules to block all untrusted access to the web management interface.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the lack of a current firmware patch, administrators must immediately implement network-level segmentation to restrict access to these devices. Once Anviz releases updated firmware, prioritize the deployment to all affected units to close the unauthorized configuration modification vector.