Vulnerability Description
Anviz CX2 Lite and CX7 are vulnerable to unauthenticated access that discloses debug configuration details (e.g., SSH/RTTY status), assisting attackers in reconnaissance against the device.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Anviz | Cx7 Firmware | - |
| Anviz | Cx7 | - |
| Anviz | Cx2 Lite Firmware | - |
| Anviz | Cx2 Lite | - |
Related Weaknesses (CWE)
References
- https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-10Third Party Advisory
- https://www.anviz.com/contact-us.htmlProduct
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-106-03US Government Resource
FAQ
What is CVE-2026-32648?
CVE-2026-32648 is a vulnerability with a CVSS score of 5.3 (MEDIUM). Anviz CX2 Lite and CX7 are vulnerable to unauthenticated access that discloses debug configuration details (e.g., SSH/RTTY status), assisting attackers in reconnaissance against the device.
How severe is CVE-2026-32648?
CVE-2026-32648 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-32648?
Check the references section above for vendor advisories and patch information. Affected products include: Anviz Cx7 Firmware, Anviz Cx7, Anviz Cx2 Lite Firmware, Anviz Cx2 Lite.