CVE-2026-7703
7.3AV Stumpfl · Pixera Two Media Server
A code injection vulnerability in the AV Stumpfl Pixera Two Media Server Websocket API allows unauthenticated remote attackers to execute arbitrary commands.
Executive summary
An unauthenticated remote code injection vulnerability in AV Stumpfl Pixera Two Media Server allows attackers to execute arbitrary system commands via the default Websocket API.
Vulnerability
This flaw involves code injection through an inadequately restricted Websocket API, allowing unauthenticated network-adjacent or remote attackers to achieve remote code execution.
Business impact
A successful exploit grants attackers complete control over the affected media server with elevated privileges, potentially leading to full system compromise, data theft, and lateral movement across internal networks. The CVSS score of 7.3 reflects the severe potential for system disruption and unauthorized access, though network segmentation can slightly limit exposure.
Remediation
Immediate Action: Update AV Stumpfl Pixera Two Media Server to version 25.2 R3 or later where API allow-listing is enabled by default.
Proactive Monitoring: Monitor network traffic on port 1338 for unusual Websocket activity and review system logs for unauthorized command execution or spawned processes.
Compensating Controls: Implement strict network perimeter controls and IP whitelisting to restrict access to the media server management interface and API endpoints to trusted administrative hosts.
Exploitation status
Public Exploit Available: Yes, a public proof-of-concept exists in a GitHub Gist referenced by the vulnerability disclosures.
Analyst recommendation
Administrators must treat this vulnerability with high urgency due to the availability of proof-of-concept code and the risk of unauthenticated remote code execution. Apply the vendor update to version 25.2 R3 immediately, and ensure network firewalls block unauthorized external access to the affected media server ports.
Sources
Originally found and disclosed by trebledj (VulDB User), per the CVE Program record.