CVE-2026-40461
CVE-2026-40461 is a high-severity vulnerability in Anviz Cx7 Firmware with a CVSS 3.x base score of 7.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-306.
Key facts
- Severity: High (CVSS 3.x base score 7.5)
- EPSS exploit prediction: 0% (39th percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2026-23498
- Weakness: CWE-306
- Affected product: Anviz Cx7 Firmware
- Published:
- Last modified:
Description
Anviz CX2 Lite and CX7 are vulnerable to unauthenticated POST requests that modify debug settings (e.g., enabling SSH), allowing unauthorized state changes that can facilitate later compromise.
Frequently asked questions
- What is CVE-2026-40461?
- Anviz CX2 Lite and CX7 are vulnerable to unauthenticated POST requests that modify debug settings (e.g., enabling SSH), allowing unauthorized state changes that can facilitate later compromise.
- How severe is CVE-2026-40461?
- CVE-2026-40461 has a CVSS 3.x base score of 7.5, rated high severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is none, integrity high, and availability none.
- Is CVE-2026-40461 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (39th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-40461?
- CVE-2026-40461 primarily affects Anviz Cx7 Firmware. In total, 2 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2026-40461?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- Does CVE-2026-40461 have an EU (EUVD) identifier?
- Yes. CVE-2026-40461 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2026-23498.
- When was CVE-2026-40461 published?
- CVE-2026-40461 was published on 2026-04-17 and last updated on 2026-06-17.
References
- https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-106-03.json
- https://www.anviz.com/contact-us.html
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-106-03
Affected products (2)
- cpe:2.3:o:anviz:cx7_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:anviz:cx2_lite_firmware:-:*:*:*:*:*:*:*
More vulnerabilities in Anviz Cx7 Firmware
- CVE-2026-35546 — Critical (CVSS 9.8): Anviz CX2 Lite and CX7 are vulnerable to unauthenticated firmware uploads. This causes crafted archives to be…
- CVE-2026-40066 — High (CVSS 8.8): Anviz CX2 Lite and CX7 are vulnerable to unverified update packages that can be uploaded. The device unpacks and…
- CVE-2026-32324 — High (CVSS 7.7): Anviz CX7 Firmware is vulnerable because the application embeds reusable certificate/key material, enabling…
- CVE-2026-33569 — Medium (CVSS 6.5): Anviz CX2 Lite and CX7 administrative sessions occur over HTTP, enabling on‑path attackers to sniff credentials and…
- CVE-2026-35061 — Medium (CVSS 5.3): Anviz CX7 Firmware is vulnerable to the most recently captured test photo that can be retrieved without…
- CVE-2026-33093 — Medium (CVSS 5.3): Anviz CX7 Firmware is vulnerable to an unauthenticated POST to the device that captures a photo with the front facing…
All CVEs affecting Anviz Cx7 Firmware →
Other CWE-306 (Missing Authentication for Critical Function) vulnerabilities
- CVE-2026-63692 — Critical (CVSS 10.0): Dell Container Storage Modules, versions prior to 1.18.0, contain(s) a Missing Authentication for Critical Function…
- CVE-2026-63688 — Critical (CVSS 10.0): Dell Container Storage Modules (CSM), versions prior to v1.18.0, contains a Missing Authentication for Critical…
- CVE-2026-103956 — Critical (CVSS 10.0): Missing authentication for critical function in the authentication dependency in Loom for AWS before 1.6.1 allowed…
- CVE-2026-53988 — Critical (CVSS 10.0): Dockhand before 1.0.40 contains an authentication bypass vulnerability in its git webhook endpoints that allows…
- CVE-2026-85889 — Critical (CVSS 10.0): Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges…
- CVE-2026-92808 — Critical (CVSS 10.0): A server-side request forgery (SSRF) vulnerability exists in the UnifiedLogin service of Altium Enterprise Server. An…
Browse all CWE-306 (Missing Authentication for Critical Function) vulnerabilities →