Back to VulnFeed / CVE-2026-7703
root@hackertop:~/vulnfeed/CVE-2026-7703#
CVE-2026-7703 MEDIUM Injection ⚠ Unpatched · Zero-day◉ PoC 公开 Lifecycle 4/7

AV Stumpfl Pixera Two Media Server up to 25.2 R2 Websocket API code injection

Pixera Two Media Server 18d ago Impact pending confirmation
LIFECYCLE
6.6 CVSS
Vulnerability Detail Mitigation Lifecycle CVSS Assessment
Vulnerability Description
A vulnerability was found in AV Stumpfl Pixera Two Media Server up to 25.2 R2. It has been rated as critical. Affected by this issue is an unknown functionality of the component Websocket API. Upgrading to version 25.2 R3 eliminates this vulnerability. The upgrade is hosted for download at help.pixera.one.
Root Cause Analysis
Using CWE to declare the problem leads to CWE-94. The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Impact: Impacted is confidentiality, integrity, and availability.

Exploit: The exploit is available at gist.github.com. It is declared as proof-of-concept.

Countermeasure: Upgrading to version 25.2 R3 eliminates this vulnerability. The upgrade is hosted for download at help.pixera.one.
Validation (PoC/EXP) - Looking for Contributors
No public PoC yet

Public validation traces already exist. Community contributors can extend them with richer reproduction content.

Contribute Your PoC/EXP
Log in to contribute PoC/EXP content. Log in
Back to VulnFeed
CVE-2026-7703 · CVSS 6.6 · Active Threat