


Perceptive Security
SOC/SIEM Consultancy

A flaw has been found in AV Stumpfl Pixera Two Media Server up to 25.2 R2. Impacted is an unknown function of the component Websocket API. This manipulation cau…
Published:
2 mei 2026 om 22:00:00
Alert date:
3 mei 2026 om 18:00:46
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications
A critical code injection vulnerability (CVE-2026-7703) has been discovered in AV Stumpfl Pixera Two Media Server up to version 25.2 R2. The flaw affects an unknown function within the WebSocket API component, allowing remote attackers to execute code injection attacks. The vulnerability can be exploited remotely and a public exploit has been published, making it actively exploitable. Users are strongly advised to upgrade to version 25.2 R3 or later to mitigate this security risk. The vulnerability poses a high risk due to its remote exploitability and the availability of public exploit code.
Technical details
Mitigation steps:
Affected products:
AV Stumpfl Pixera Two Media Server
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-7703
https://gist.github.com/TrebledJ/585a20525e45549f299d282233632608
https://help.pixera.one/changelogs-version-overviews/pixera-252-overview-changelog
https://vuldb.com/submit/805274
https://vuldb.com/vuln/360872
https://vuldb.com/vuln/360872/cti
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
