CVE-2026-40066 affects Anviz CX2 Lite and CX7 devices through an unverified update package upload vulnerability that enables unauthenticated remote code execution. The flaw allows attackers to upload malicious update packages that the devices automatically unpack and execute without proper verification mechanisms. This vulnerability carries a CVSS score of 8.8 (HIGH) with a network-based attack vector requiring low complexity and low privileges, resulting in complete compromise of confidentiality, integrity, and availability. The vulnerability is currently listed on the active Hot List, indicating heightened community attention and ongoing monitoring, though it is not yet widely exploited based on EPSS metrics. Organizations running affected Anviz devices should prioritize patching efforts given the high severity rating and unauthenticated nature of the attack vector.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:anviz:cx7_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:anviz:cx2_lite_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.