CVE-2026-31927: Anviz CX7 Firmware

Medium severity, CVSS 4.9. EPSS: 0.5% chance of exploitation in the next 30 days.

Anviz CX7 Firmware is vulnerable to an authenticated CSV upload which allows path traversal to overwrite arbitrary files (e.g., /etc/shadow), enabling unauthorized SSH access when combined with debug‑setting changes.

Affected products

  • Anviz CX7 Firmware: affected versions not specified

Published 2026-04-17. Last modified 2026-07-10.