CVE-2026-33569 PUBLISHED

Anviz Products Cleartext Transmission of Sensitive Information

Assigner: icscert
Reserved: 14.04.2026 Published: 17.04.2026 Updated: 17.04.2026

Anviz CX2 Lite and CX7 administrative sessions occur over HTTP, enabling on‑path attackers to sniff credentials and session data, which can be used to compromise the device.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CVSS Score: 6.5

Product Status

Vendor Anviz
Product Anviz CX7 Firmware
Versions Default: unaffected
  • Version All versions is affected
Vendor Anviz
Product Anviz CX2 Lite Firmware
Versions Default: unaffected
  • Version All versions is affected

Workarounds

Anviz did not respond to CISA's attempts to coordinate these vulnerabilities. Users should contact Anviz for more information at https://www.anviz.com/contact-us.html.

References

Problem Types

  • CWE-319 CWE