CVE-2026-35546 is a critical vulnerability affecting Anviz CX2 Lite and CX7 devices that allows unauthenticated attackers to upload malicious firmware through crafted archives, potentially leading to remote code execution and reverse shell access. The vulnerability carries a CVSS score of 9.8 (Critical) due to its network-accessible attack vector, low complexity, lack of authentication requirements, and high impact across confidentiality, integrity, and availability. The attack requires no user interaction and can be executed by a remote, unauthenticated attacker with minimal effort. While exploitation data is currently limited with an EPSS score of 0.00078 and no confirmed Common Vulnerabilities and Exposures (KEV) catalog inclusion, the vulnerability is actively tracked on threat intelligence hot lists, warranting immediate attention. Organizations deploying these Anviz devices should prioritize patching or implementing network-level access controls to restrict firmware upload functionality pending vendor remediation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:anviz:cx7_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:anviz:cx2_lite_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.