CVE-2026-35546
CRITICAL
NVD
CVSS Score
9.8
Severity
CRITICAL
Published
Apr 17, 2026
Vendor
unknown
Description
Anviz CX2 Lite and CX7 are vulnerable to unauthenticated firmware uploads. This causes crafted archives to be accepted, enabling attackers to plant and execute code and obtain a reverse shell.