Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Anviz

First CVE: Jun 6, 2019Active for: 7 yearsTotal CVEs: 21
45.7
VTI Score
High

Anviz develops a focused portfolio of physical access control and time-and-attendance systems, including firmware, on-premises management platforms, and cloud-connected solutions such as CrossChex and the M3 device line, serving facilities and enterprise deployments. Vulnerabilities affecting the vendor skew toward serious outcomes, with a significant share reaching critical severity, and recur across the product family through authentication and authorization weaknesses—including missing authentication on critical functions, improper privilege checks, and capture-replay flaws—alongside cleartext transmission of sensitive credentials and classic buffer-overflow conditions in firmware components. These weakness classes reflect both the network-facing nature of access-control appliances and the legacy embedded practices in device firmware, creating risk that concentrates in internet-reachable or management-adjacent system boundaries. Defenders should prioritize inventory of Anviz deployments in network segments controlling physical access, apply segmentation to isolate management traffic, and treat firmware updates as high-priority given the severity profile; current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
21
Total CVEs
More Total CVEs than 96% of tracked vendors
1.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 74% of tracked vendors
7.6
Avg CVSS Score
Higher Avg CVSS Score than 72% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Anviz over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 6, 2019
7 years ago
Most Recent CVE
Apr 17, 2026
98 days ago

Products(10 total)

Top CVEs

Signals from CVEs in this vendor scope (21 CVEs).

21 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-12518CRITICAL
Anviz CrossChex access control management software 4.3.8.0 and 4.3.12 is vulnerable to a buffer overflow vulnerability.
Dec 2, 20199.877NOYES
CVE-2026-35546CRITICAL
Anviz CX2 Lite and CX7 are vulnerable to unauthenticated firmware uploads. This causes crafted archives to be accepted, enabling attackers to plant and execute code and obtain a
Apr 17, 20269.833NONO
CVE-2026-40066HIGH
Anviz CX2 Lite and CX7 are vulnerable to unverified update packages that can be uploaded. The device unpacks and executes a script resulting in unauthenticated remote code executio
Apr 17, 20268.832NONO
CVE-2019-11523CRITICAL
Anviz Global M3 Outdoor RFID Access Control executes any command received from any source. No authentication/encryption is done. Attackers can fully interact with the device: for e
Jun 6, 20199.831NONO
CVE-2019-12392CRITICAL
Anviz access control devices allow remote attackers to issue commands without a password.
Dec 2, 20199.830NONO
CVE-2026-35682HIGH
Anviz CX2 Lite is vulnerable to an authenticated command injection via a filename parameter that enables arbitrary command execution (e.g., starting telnetd), resulting in root‑l
Apr 17, 20268.829NONO
CVE-2019-12394CRITICAL
Anviz access control devices allow unverified password change which allows remote attackers to change the administrator password without prior authentication.
Dec 2, 20199.829NONO
CVE-2026-40434HIGH
Anviz CrossChex Standard lacks source verification in the client/server channel, enabling TCP packet injection by an attacker on the same network to alter or disrupt application
Apr 17, 20268.127NONO
CVE-2026-40461HIGH
Anviz CX2 Lite and CX7 are vulnerable to unauthenticated POST requests that modify debug settings (e.g., enabling SSH), allowing unauthorized state changes that can facilitate la
Apr 17, 20267.525NONO
CVE-2019-12389HIGH
Anviz access control devices expose credentials (names and passwords) by allowing remote attackers to query this information without credentials via port tcp/5010.
Dec 2, 20197.525NONO
View all 21 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products21 CVEs
29%
48%
24%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (4.8%)
Network19 (90.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (4.8%)
Attack Complexity
Low21 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None20 (95.2%)
Unknown0 (0.0%)
Required1 (4.8%)
Privileges Required
Low2 (9.5%)
High1 (4.8%)
None18 (85.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (21 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
4.8% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
4.8% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Anviz.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Anviz — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Anviz's Products

View all 2 CNAs →

Top CWEs