← Vulnerability feed

Vulnerability record · CVE-2026-32324 · published 17 April 2026

CVE-2026-32324: Anviz cx7 firmware vulnerability

Anviz · Cx7 Firmware

Anviz CX7 Firmware is  vulnerable because the application embeds reusable certificate/key material, enabling decryption of MQTT traffic and potential interaction with device messaging channels at scale.

7.7 CVSS 3.1 High EPSS 0.12% · top 98.4% CWE-321 · CWE-321
7.7CVSS 3.1 base score
0.12%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

Anviz CX7 Firmware is  vulnerable because the application embeds reusable certificate/key material, enabling decryption of MQTT traffic and potential interaction with device messaging channels at scale.

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-32324 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-35546Anviz cx7 firmware missing authentication for critical function vulnerabilityAnviz CX2 Lite and CX7 are vulnerable to unauthenticated firmware uploads. This causes crafted archives to be accepted, enabling attackers to plant a…EPSS 0.82%8.8CVE-2026-40066Anviz cx7 firmware download of code without integrity check vulnerabilityAnviz CX2 Lite and CX7 are vulnerable to unverified update packages that can be uploaded. The device unpacks and executes a script resulting in unaut…EPSS 0.54%7.5CVE-2026-40461Anviz cx7 firmware missing authentication for critical function vulnerabilityAnviz CX2 Lite and CX7 are vulnerable to unauthenticated POST requests that modify debug settings (e.g., enabling SSH), allowing unauthorized state c…EPSS 0.48%6.5CVE-2026-33569Anviz cx7 firmware cleartext transmission vulnerabilityAnviz CX2 Lite and CX7 administrative sessions occur over HTTP, enabling on‑path attackers to sniff credentials and session data, which can be used t…EPSS 0.31%5.3CVE-2026-35061Anviz cx7 firmware missing authorization vulnerabilityAnviz CX7 Firmware is vulnerable to the most recently captured test photo that can be retrieved without authentication, revealing sensitive operation…EPSS 0.52%5.3CVE-2026-32648Anviz cx7 firmware missing authorization vulnerabilityAnviz CX2 Lite and CX7 are vulnerable to unauthenticated access that discloses debug configuration details (e.g., SSH/RTTY status), assisting attacke…EPSS 0.42%5.3CVE-2026-33093Anviz cx7 firmware missing authorization vulnerabilityAnviz CX7 Firmware is vulnerable to an unauthenticated POST to the device that captures a photo with the front facing camera, exposing visual informa…EPSS 0.42%4.9CVE-2026-31927Anviz cx7 firmware relative path traversal vulnerabilityAnviz CX7 Firmware is vulnerable to an authenticated CSV upload which allows path traversal to overwrite arbitrary files (e.g., /etc/shadow), enablin…EPSS 0.52%

Source: NIST National Vulnerability Database (record CVE-2026-32324), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.