CVE-2026-35682 is an authenticated command injection vulnerability in Anviz CX2 Lite that allows attackers to execute arbitrary commands through a malicious filename parameter, potentially gaining root-level access to affected systems. The vulnerability carries a CVSS score of 8.8 (High severity) with a network-based attack vector requiring low complexity and valid user credentials; it enables complete compromise of system confidentiality, integrity, and availability. Currently, there is no evidence of active exploitation in the wild, as the vulnerability does not appear on the KEV catalog or active threat lists, though the EPSS score of 0.0027 indicates a relatively low probability of exploitation compared to the broader CVE population.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:anviz:cx2_lite_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.