CVE-2026-40461: Anviz CX2 Lite Firmware
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
Anviz CX2 Lite and CX7 are vulnerable to unauthenticated POST requests that modify debug settings (e.g., enabling SSH), allowing unauthorized state changes that can facilitate later compromise.
Affected products
- Anviz CX2 Lite Firmware: affected versions not specified
- Anviz CX7 Firmware: affected versions not specified
Published 2026-04-17. Last modified 2026-06-17.