CVE-2026-40066
Anviz CX2 Lite and CX7 are vulnerable to unverified update packages that can be uploaded. The
device unpacks and exec
Anviz CX2 Lite and CX7 are vulnerable to unverified update packages that can be uploaded. The device unpacks and executes a script resulting in unauthenticated remote code execution.
HIGH · CVSS 8.8
EPSS 0.00029
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0