Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Critical

Unauthenticated Firmware Upload RCE in Anviz CX2 Lite and CX7

IdentifiersCVE-2026-35546CWE-306· Missing Authentication for…

CVE-2026-35546 affects Anviz CX2 Lite and CX7 devices and consists of missing authentication on a critical firmware upload function. The affected devices accept unauthenticated firmware uploads, and crafted archive files can be submitted without prior authentication. Because the upload mechanism accepts attacker-controlled archives, a remote attacker can plant malicious content on the device, trigger execution of attacker-supplied code, and obtain a reverse shell. The available reporting characterizes the issue as remotely exploitable over the network with low attack complexity and no user interaction.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation can lead to unauthenticated remote code execution on the affected device. An attacker can implant malicious code, execute arbitrary commands in the device context, and establish a reverse shell for persistent interactive access. Given the reported CVSS vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, the impact is high across confidentiality, integrity, and availability, and may result in full compromise of the device.

Mitigation

If you can’t patch tonight, do this now.

Until patches are fully deployed, minimize network exposure of affected devices, do not expose them directly to the internet, place them behind firewalls, and isolate them from business networks as recommended by CISA. Restrict access to device management and firmware update interfaces to trusted administrative networks only. Use secure remote access methods such as VPNs where remote administration is required, and perform impact analysis and risk assessment before applying defensive changes in operational environments. Monitoring for unexpected firmware uploads, outbound reverse-shell behavior, and other anomalous management-plane activity is also advisable.

Remediation

Patch, then assume compromise.

Apply the vendor-provided fix or updated firmware referenced by Anviz and the associated CISA ICS advisory for the affected CX2 Lite and CX7 products. Because the vulnerability is in the firmware upload mechanism, remediation should specifically ensure that firmware upload and update paths require authentication and reject unauthorized or malformed crafted archives. If a vendor patch is available, prioritize upgrading affected devices to the remediated version as soon as operationally feasible.
PUBLIC EXPLOITS

Exploits

No public exploits tracked yet. Mallory keeps watching.

VALID 0 / 0 TOTALView more in app

No public exploit code observed for this vulnerability.

EXPOSURE SURFACE

Affected products & vendors

Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.

VendorProductType
AnvizCx2 Litehardware
AnvizCx2 Lite Firmwareoperating_system
AnvizCx7hardware
AnvizCx7 Firmwareoperating_system

Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence

Every observed campaign linking this CVE to a named adversary.

Associated malware

Malware families riding this exploit, with evidence and IOCs.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity4

Community discussion across Reddit, Mastodon, and other social sources.