


Perceptive Security
SOC/SIEM Consultancy

Anviz CX2 Lite and CX7 are vulnerable to unauthenticated firmware uploads. This causes crafted
archives to be accepted, enabling attackers to plant and execute…
Published:
16 april 2026 om 22:00:00
Alert date:
17 april 2026 om 21:03:48
Source:
nvd.nist.gov
Mobile & IoT, Critical Infrastructure
Anviz CX2 Lite and CX7 devices are vulnerable to unauthenticated firmware uploads that allow attackers to upload crafted archives. This vulnerability enables attackers to plant and execute malicious code on the affected devices. Successful exploitation can lead to complete system compromise and the ability to obtain a reverse shell. The vulnerability affects access control devices commonly used in enterprise environments. No authentication is required to exploit this vulnerability, making it particularly dangerous.
Technical details
Mitigation steps:
Affected products:
Anviz CX2 Lite
Anviz CX7
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-35546
https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-106-03.json
https://www.anviz.com/contact-us.html
https://www.cisa.gov/news-events/ics-advisories/icsa-26-106-03
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
