Weakness
Anviz CX2 Lite and CX7 are vulnerable to unauthenticated firmware uploads. This causes crafted archives to be accepted, enabling attackers to plant and execute code and obtain a reverse shell.
Affected products
- anviz cx7_firmware
- anviz cx7
- anviz cx2_lite_firmware
- anviz cx2_lite
References
Find the bug before an attacker does.
Sign in with GitHub and run your first audit in under a minute. The free plan needs no credit card.