Back to VulnFeed / CVE-2026-7704
root@hackertop:~/vulnfeed/CVE-2026-7704#
CVE-2026-7704 LOW Path Traversal ⚠ Unpatched · Zero-day◉ PoC 公开 Lifecycle 4/7

AV Stumpfl Pixera Two Media Server up to 25.1 R2 Service Port 1338 path traversal

Pixera Two Media Server 18d ago Impact pending confirmation
LIFECYCLE
3.9 CVSS
Vulnerability Detail Mitigation Lifecycle CVSS Assessment
Vulnerability Description
A vulnerability classified as problematic has been found in AV Stumpfl Pixera Two Media Server up to 25.1 R2. This affects some unknown functionality of the component Service Port 1338. Upgrading to version 25.2 R3 eliminates this vulnerability. The upgrade is hosted for download at help.pixera.one.
Root Cause Analysis
CWE is classifying the issue as CWE-22. The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Impact: This is going to have an impact on confidentiality.

Exploit: The exploit is shared for download at gist.github.com. It is declared as proof-of-concept.

Countermeasure: Upgrading to version 25.2 R3 eliminates this vulnerability. The upgrade is hosted for download at help.pixera.one.
Validation (PoC/EXP) - Looking for Contributors
No public PoC yet

Public validation traces already exist. Community contributors can extend them with richer reproduction content.

Contribute Your PoC/EXP
Log in to contribute PoC/EXP content. Log in
Back to VulnFeed
CVE-2026-7704 · CVSS 3.9 · Active Threat