PT-2026-33486 · Anviz · Anviz Cx7 Firmware

Published

2026-04-17

·

Updated

2026-04-17

·

CVE-2026-31927

CVSS v3.1

4.9

Medium

AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
Anviz CX7 Firmware is vulnerable to an authenticated CSV upload which allows path traversal to overwrite arbitrary files (e.g., /etc/shadow), enabling unauthorized SSH access when combined with debug‑setting changes

Fix

Relative Path Traversal

Weakness Enumeration

Related Identifiers

CVE-2026-31927

Affected Products

Anviz Cx7 Firmware