CVE-2026-33569
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: ics-cert@hq.dhs.gov (Secondary)
Description
Anviz CX2 Lite and CX7 administrative sessions occur over HTTP, enabling
on‑path attackers to sniff credentials and session data, which can be
used to compromise the device.
Affected (2)
Products: Anviz: Cx7 Firmware, Cx2 Lite Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Anviz Cx7 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Anviz Cx2 Lite | All versions |
References (3)
Source: ics-cert@hq.dhs.gov
Third Party Advisory
Source: ics-cert@hq.dhs.gov
US Government Resource
Timeline
No history available yet.