Description

Anviz CX2 Lite and CX7 are vulnerable to unverified update packages that can be uploaded. The device unpacks and executes a script resulting in unauthenticated remote code execution.

INFO

Published Date :

2026-04-17T19:43:20.709Z

Last Modified :

2026-04-17T20:00:36.786Z

Source :

icscert
AFFECTED PRODUCTS

The following products are affected by CVE-2026-40066 vulnerability.

Vendors Products
Anviz
  • Anviz Cx2 Lite Firmware
  • Anviz Cx7 Firmware
REFERENCES

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact