cx7_firmware vulnerabilities
CVEs whose affected-version data names the cx7_firmware package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-40066High· 8.8Anviz CX2 Lite and CX7 are vulnerable to unverified update packages that can be uploaded
Anviz CX2 Lite and CX7 are vulnerable to unverified update packages that can be uploaded. The device unpacks and executes a script resulting in unauthenticated remote code execution.
▾ Twilightanviz · cx7_firmwareEPSS 0.41%via NVD
CVE-2026-31927Medium· 4.9Anviz CX7 Firmware is vulnerable to an authenticated CSV upload which allows path traversal to overwrite arbitrary files (e.g., /etc/shadow), enabling unauthorized SSH access when combined with debug‑setting changes.
Anviz CX7 Firmware is vulnerable to an authenticated CSV upload which allows path traversal to overwrite arbitrary files (e.g., /etc/shadow), enabling unauthorized SSH access when combined with debug‑setting changes.
▾ Sunlitanviz · cx7_firmwareEPSS 0.35%via NVD