CVE-2026-40066
EUVD-2026-2349417.04.2026, 20:16
Anviz CX2 Lite and CX7 are vulnerable to unverified update packages that can be uploaded. The device unpacks and executes a script resulting in unauthenticated remote code execution.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| anviz | cx7_firmware | - |
| anviz | cx2_lite_firmware | - |
𝑥
= Vulnerable software versions
Common Weakness Enumeration