Cyber Posture

CVE-2026-40461

High

Published: 17 April 2026

Published
17 April 2026
Modified
04 May 2026
KEV Added
Patch
CVSS Score 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS Score 0.0003 9.1th percentile
Risk Priority 15 60% EPSS · 20% KEV · 20% CVSS

Summary

CVE-2026-40461 is a high-severity Missing Authentication for Critical Function (CWE-306) vulnerability in Anviz Cx7 Firmware. Its CVSS base score is 7.5 (High).

Operationally, exploitation aligns with the MITRE ATT&CK technique Exploit Public-Facing Application (T1190); ranked at the 9.1th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

The strongest mitigations our analysis identified are NIST 800-53 AC-14 (Permitted Actions Without Identification or Authentication) and AC-3 (Access Enforcement).

Threat & Defense at a Glance

What attackers do: exploitation maps to Exploit Public-Facing Application (T1190) and 1 other technique. What defenders deploy: see the NIST 800-53 controls recommended below.
Threat & Defense Details

Mitigating Controls (NIST 800-53 r5)AI

prevent

Directly requires identification and documentation of actions permitted without authentication, preventing unauthenticated POST requests from modifying critical debug settings.

prevent

Enforces approved authorizations for access to system resources, blocking unauthorized state changes via unauthenticated requests.

prevent

Restricts and manages access to configuration change mechanisms, mitigating unauthorized modifications to debug configurations like enabling SSH.

MITRE ATT&CK Enterprise TechniquesAI

T1190 Exploit Public-Facing Application Initial Access
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
T1021.004 SSH Lateral Movement
Adversaries may use [Valid Accounts](https://attack.
Why these techniques?

The vulnerability permits remote unauthenticated changes to debug settings enabling SSH on network-accessible devices, enabling exploitation of public-facing applications (T1190) and facilitating remote access via SSH (T1021.004).

Confidence: HIGH · MITRE ATT&CK Enterprise v18.1

NVD Description

Anviz CX2 Lite and CX7 are vulnerable to unauthenticated POST requests that modify debug settings (e.g., enabling SSH), allowing unauthorized state changes that can facilitate later compromise.

Deeper analysisAI

CVE-2026-40461 is a vulnerability in Anviz CX2 Lite and CX7 access control devices that allows unauthenticated POST requests to modify debug settings, such as enabling SSH. This enables unauthorized state changes that can facilitate later compromise of the devices. The issue is rated with a CVSS v3.1 base score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N) and is associated with CWE-306 (Missing Authentication for Critical Function). It was published on 2026-04-17.

An attacker with network access to an affected device can exploit this vulnerability remotely without authentication, privileges, or user interaction. By sending crafted POST requests, the attacker can alter debug configurations, for instance enabling SSH, which creates opportunities for subsequent unauthorized access and device compromise, primarily impacting integrity.

Official mitigation guidance is provided in CISA ICS Advisory ICSA-26-106-03 (https://www.cisa.gov/news-events/ics-advisories/icsa-26-106-03) and the corresponding CSAF JSON file (https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-106-03.json). Vendor support is available via Anviz at https://www.anviz.com/contact-us.html.

Details

CWE(s)

Affected Products

anviz
cx7 firmware
all versions
anviz
cx2 lite firmware
all versions

CVEs Like This One

CVE-2026-35546Same product: Anviz Cx2 Lite
CVE-2026-40066Same product: Anviz Cx2 Lite
CVE-2026-32324Same product: Anviz Cx7
CVE-2026-35682Same product: Anviz Cx2 Lite
CVE-2026-32650Same vendor: Anviz
CVE-2026-1453Shared CWE-306
CVE-2026-31882Shared CWE-306
CVE-2025-27642Shared CWE-306
CVE-2021-47891Shared CWE-306
CVE-2026-26340Shared CWE-306

References