Junglewise Threat Intelligence

CVE-2026-40066: Anviz CX2 Lite and CX7 remote code execution via unverified updates

CVE-2026-40066 · Severity: high · CVSS 8.8 · Published 2026-04-17

Executive brief

Anviz CX2 Lite and CX7 facial recognition and time attendance devices are vulnerable to a security flaw in their update mechanism. An attacker can upload a malicious update package that the device will automatically unpack and execute. This allows an attacker to take full control of the device, potentially disrupting physical access control or stealing sensitive data.

Technical details

Anviz CX2 Lite and CX7 firmware versions are vulnerable to CWE-494 (Download of Code Without Integrity Check). The devices allow the upload of update packages that are not properly verified for authenticity or integrity. Upon upload, the device automatically unpacks the package and executes contained scripts. This flaw enables an attacker with network access to achieve remote code execution (RCE) with high privileges. While the CVSS vector indicates low privileges are required, the summary describes the result as unauthenticated RCE. As of the advisory date, the vendor has not provided a patch, and users are advised to contact Anviz for support.

Affected products

  • Anviz CX2 Lite Firmware All versions
  • Anviz CX7 Firmware All versions

Timeline

  • 2026-04-16: advisory: CISA published ICSA-26-106-03
  • 2026-04-17: disclosed: CVE-2026-40066 published in NVD

References

Related threats