Home

Description

Anviz CX2 Lite and CX7 are vulnerable to unauthenticated POST requests that modify debug settings (e.g., enabling SSH), allowing unauthorized state changes that can facilitate later compromise.

PUBLISHED Reserved 2026-04-14 | Published 2026-04-17 | Updated 2026-04-17 | Assigner icscert




HIGH: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Problem types

CWE-306

Product status

Default status
unaffected

All versions
affected

Default status
unaffected

All versions
affected

References

www.anviz.com/contact-us.html

www.cisa.gov/news-events/ics-advisories/icsa-26-106-03

github.com/...p/csaf_files/OT/white/2026/icsa-26-106-03.json

cve.org (CVE-2026-40461)

nvd.nist.gov (CVE-2026-40461)

Download JSON