Junglewise Threat Intelligence

CVE-2026-31927: Anviz CX7 Firmware path traversal via CSV upload

CVE-2026-31927 · Severity: medium · CVSS 4.9 · Published 2026-04-17

Executive brief

Anviz CX7 facial recognition and time attendance devices are affected by a security flaw in how they handle file uploads. An authorized user with high-level permissions can exploit this to overwrite critical system files, which could allow them to gain full administrative control (root access) over the device. This could lead to unauthorized access to the building or tampering with employee time records.

Technical details

Anviz CX7 firmware contains a relative path traversal vulnerability (CWE-23) within its CSV upload functionality. An authenticated attacker with high privileges can craft a malicious CSV upload to overwrite arbitrary files on the local filesystem, such as /etc/shadow. When combined with other vulnerabilities that allow modifying debug settings to enable SSH, this flaw enables an attacker to gain unauthorized root-level SSH access to the device. As of the advisory date, the vendor has not responded to coordination attempts, and no official patch is available.

Affected products

  • Anviz CX7 Firmware All versions

Timeline

  • 2026-04-16: advisory: CISA ICSA-26-106-03 published
  • 2026-04-17: disclosed: CVE-2026-31927 published to NVD

References

Related threats