Executive brief
Anviz CX7 facial recognition and time attendance devices are affected by a security flaw in how they handle file uploads. An authorized user with high-level permissions can exploit this to overwrite critical system files, which could allow them to gain full administrative control (root access) over the device. This could lead to unauthorized access to the building or tampering with employee time records.
Technical details
Anviz CX7 firmware contains a relative path traversal vulnerability (CWE-23) within its CSV upload functionality. An authenticated attacker with high privileges can craft a malicious CSV upload to overwrite arbitrary files on the local filesystem, such as /etc/shadow. When combined with other vulnerabilities that allow modifying debug settings to enable SSH, this flaw enables an attacker to gain unauthorized root-level SSH access to the device. As of the advisory date, the vendor has not responded to coordination attempts, and no official patch is available.
Affected products
- Anviz CX7 Firmware All versions
Timeline
- 2026-04-16: advisory: CISA ICSA-26-106-03 published
- 2026-04-17: disclosed: CVE-2026-31927 published to NVD