vulnerable because the application embeds reusable certificate/key
material, enabling decryption of MQTT traffic and potential interaction
with device messaging channels at scale.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
Anviz did not respond to CISA's attempts to coordinate these vulnerabilities. Users should contact Anviz for more information at https://www.anviz.com/contact-us.html.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 04 May 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Anviz cx7
Anviz cx7 Firmware |
|
| CPEs | cpe:2.3:h:anviz:cx7:-:*:*:*:*:*:*:* cpe:2.3:o:anviz:cx7_firmware:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Anviz cx7
Anviz cx7 Firmware |
Mon, 20 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Anviz
Anviz anviz Cx7 Firmware |
|
| Vendors & Products |
Anviz
Anviz anviz Cx7 Firmware |
Fri, 17 Apr 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 17 Apr 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Anviz CX7 Firmware is vulnerable because the application embeds reusable certificate/key material, enabling decryption of MQTT traffic and potential interaction with device messaging channels at scale. | |
| Title | Anviz CX7 Firmware Use of Hard-coded Cryptographic Key | |
| Weaknesses | CWE-321 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-04-17T20:10:48.189Z
Reserved: 2026-04-14T15:47:54.287Z
Link: CVE-2026-32324
Updated: 2026-04-17T20:10:41.733Z
Status : Analyzed
Published: 2026-04-17T20:16:33.817
Modified: 2026-05-04T14:31:57.447
Link: CVE-2026-32324
No data.
OpenCVE Enrichment
Updated: 2026-04-20T15:05:23Z