VYPR
High severity8.8NVD Advisory· Published Apr 17, 2026· Updated May 4, 2026

CVE-2026-35682

CVE-2026-35682

Description

Anviz CX2 Lite is vulnerable to an authenticated command injection via a filename parameter that enables arbitrary command execution (e.g., starting telnetd), resulting in root‑level access.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.