CVE-2026-31927

Severity CVSS v4.0:
Pending analysis
Type:
CWE-23 Relative Path Traversal
Publication date:
17/04/2026
Last modified:
04/05/2026

Description

Anviz CX7 Firmware is vulnerable to an authenticated CSV upload which allows path traversal <br /> to overwrite arbitrary files (e.g., /etc/shadow), enabling unauthorized <br /> SSH access when combined with debug‑setting changes

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:anviz:cx7_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:anviz:cx7:-:*:*:*:*:*:*:*