Vulnerability Description
Anviz CX2 Lite and CX7 are vulnerable to unauthenticated firmware uploads. This causes crafted archives to be accepted, enabling attackers to plant and execute code and obtain a reverse shell.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Anviz | Cx7 Firmware | - |
| Anviz | Cx7 | - |
| Anviz | Cx2 Lite Firmware | - |
| Anviz | Cx2 Lite | - |
Related Weaknesses (CWE)
References
- https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-10Third Party Advisory
- https://www.anviz.com/contact-us.htmlProduct
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-106-03US Government Resource
FAQ
What is CVE-2026-35546?
CVE-2026-35546 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Anviz CX2 Lite and CX7 are vulnerable to unauthenticated firmware uploads. This causes crafted archives to be accepted, enabling attackers to plant and execute code and obtain a reverse shell.
How severe is CVE-2026-35546?
CVE-2026-35546 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-35546?
Check the references section above for vendor advisories and patch information. Affected products include: Anviz Cx7 Firmware, Anviz Cx7, Anviz Cx2 Lite Firmware, Anviz Cx2 Lite.