CVE-2026-40461 PUBLISHED

Anviz Products Missing Authentication for Critical Function

Assigner: icscert
Reserved: 14.04.2026 Published: 17.04.2026 Updated: 17.04.2026

Anviz CX2 Lite and CX7 are vulnerable to unauthenticated POST requests that modify debug settings (e.g., enabling SSH), allowing unauthorized state changes that can facilitate later compromise.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS Score: 7.5

Product Status

Vendor Anviz
Product Anviz CX7 Firmware
Versions Default: unaffected
  • Version All versions is affected
Vendor Anviz
Product Anviz CX2 Lite Firmware
Versions Default: unaffected
  • Version All versions is affected

Workarounds

Anviz did not respond to CISA's attempts to coordinate these vulnerabilities. Users should contact Anviz for more information at https://www.anviz.com/contact-us.html.

References

Problem Types

  • CWE-306 CWE