Anviz develops a focused portfolio of physical access control and time-and-attendance systems, including firmware, on-premises management platforms, and cloud-connected solutions such as CrossChex and the M3 device line, serving facilities and enterprise deployments. Vulnerabilities affecting the vendor skew toward serious outcomes, with a significant share reaching critical severity, and recur across the product family through authentication and authorization weaknesses—including missing authentication on critical functions, improper privilege checks, and capture-replay flaws—alongside cleartext transmission of sensitive credentials and classic buffer-overflow conditions in firmware components. These weakness classes reflect both the network-facing nature of access-control appliances and the legacy embedded practices in device firmware, creating risk that concentrates in internet-reachable or management-adjacent system boundaries. Defenders should prioritize inventory of Anviz deployments in network segments controlling physical access, apply segmentation to isolate management traffic, and treat firmware updates as high-priority given the severity profile; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Anviz over time
Signals from CVEs in this vendor scope (21 CVEs).
21 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-12518CRITICAL Anviz CrossChex access control management software 4.3.8.0 and 4.3.12 is vulnerable to a buffer overflow vulnerability. | Dec 2, 2019 | 9.8 | 77 | NO | YES |
CVE-2026-35546CRITICAL Anviz CX2 Lite and CX7 are vulnerable to unauthenticated firmware uploads. This causes crafted
archives to be accepted, enabling attackers to plant and execute code
and obtain a | Apr 17, 2026 | 9.8 | 33 | NO | NO |
CVE-2026-40066HIGH Anviz CX2 Lite and CX7 are vulnerable to unverified update packages that can be uploaded. The device unpacks and executes a script resulting in unauthenticated remote code executio | Apr 17, 2026 | 8.8 | 32 | NO | NO |
CVE-2019-11523CRITICAL Anviz Global M3 Outdoor RFID Access Control executes any command received from any source. No authentication/encryption is done. Attackers can fully interact with the device: for e | Jun 6, 2019 | 9.8 | 31 | NO | NO |
CVE-2019-12392CRITICAL Anviz access control devices allow remote attackers to issue commands without a password. | Dec 2, 2019 | 9.8 | 30 | NO | NO |
CVE-2026-35682HIGH Anviz CX2 Lite is vulnerable to an authenticated command injection via a
filename parameter that enables arbitrary command execution (e.g.,
starting telnetd), resulting in root‑l | Apr 17, 2026 | 8.8 | 29 | NO | NO |
CVE-2019-12394CRITICAL Anviz access control devices allow unverified password change which allows remote attackers to change the administrator password without prior authentication. | Dec 2, 2019 | 9.8 | 29 | NO | NO |
CVE-2026-40434HIGH Anviz CrossChex Standard
lacks source verification in the client/server channel, enabling TCP
packet injection by an attacker on the same network to alter or disrupt
application | Apr 17, 2026 | 8.1 | 27 | NO | NO |
CVE-2026-40461HIGH Anviz CX2 Lite and CX7 are vulnerable to unauthenticated POST requests that modify debug
settings (e.g., enabling SSH), allowing unauthorized state changes that
can facilitate la | Apr 17, 2026 | 7.5 | 25 | NO | NO |
CVE-2019-12389HIGH Anviz access control devices expose credentials (names and passwords) by allowing remote attackers to query this information without credentials via port tcp/5010. | Dec 2, 2019 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (21 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Anviz.
Media articles that mention a CVE ID that affects a product developed by Anviz — matched by CVE ID, not by vendor name.