CVE-2026-31927: Anviz CX7 Firmware
Medium severity, CVSS 4.9. EPSS: 0.5% chance of exploitation in the next 30 days.
Anviz CX7 Firmware is vulnerable to an authenticated CSV upload which allows path traversal to overwrite arbitrary files (e.g., /etc/shadow), enabling unauthorized SSH access when combined with debug‑setting changes.
Affected products
- Anviz CX7 Firmware: affected versions not specified
Published 2026-04-17. Last modified 2026-07-10.