Cyber Posture

CVE-2026-7703

High

Published: 03 May 2026

Published
03 May 2026
Modified
03 May 2026
KEV Added
Patch
CVSS Score 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
EPSS Score 0.0005 14.1th percentile
Risk Priority 15 60% EPSS · 20% KEV · 20% CVSS

Description

A flaw has been found in AV Stumpfl Pixera Two Media Server up to 25.2 R2. Impacted is an unknown function of the component Websocket API. This manipulation causes code injection. The attack can be initiated remotely. The exploit has been published and may be used. Upgrading to version 25.2 R3 is recommended to address this issue. Upgrading the affected component is advised.

Security Summary

CVE-2026-7703 is a code injection vulnerability affecting AV Stumpfl Pixera Two Media Server versions up to 25.2 R2. The flaw resides in an unknown function within the Websocket API component, allowing remote attackers to manipulate inputs and inject code. It is classified under CWE-74 (injection) and CWE-94 (code injection), with a CVSS v3.1 base score of 7.3 (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L), indicating high severity due to its network accessibility and lack of prerequisites.

Attackers can exploit this vulnerability remotely without authentication or user interaction, targeting systems exposing the Websocket API over the network. Successful exploitation enables limited impacts on confidentiality, integrity, and availability, potentially allowing arbitrary code execution within the context of the media server. An exploit has been publicly disclosed, increasing the risk of immediate abuse.

Advisories recommend upgrading to version 25.2 R3 to mitigate the issue, as detailed in the Pixera changelog. Additional resources from VulDB and a GitHub Gist provide further vulnerability details, submission records, and the exploit code itself.

The published exploit heightens the urgency for patching, as it may already be in use against exposed instances of this media server software.

Details

CWE(s)
CWE-74CWE-94

References