CVE-2026-35682

Anviz CX2 Lite is vulnerable to an authenticated command injection via a filename parameter that enables arbitrary command execution (e.g., starting telnetd), resulting in root‑level access.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:anviz:cx2_lite_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:anviz:cx2_lite:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-04-17 20:16

Updated : 2026-06-17 10:41


NVD link : CVE-2026-35682

Mitre link : CVE-2026-35682

CVE.ORG link : CVE-2026-35682


JSON object : View

Products Affected

anviz

  • cx2_lite_firmware
  • cx2_lite
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')