CVE-2026-7704 Details
Description
A vulnerability has been found in AV Stumpfl Pixera Two Media Server up to 25.1 R2. The affected element is an unknown function of the component Service Port 1338. Such manipulation leads to path traversal. The exploit has been disclosed to the public and may be used. Upgrading to version 25.2 R3 is sufficient to fix this issue. It is advisable to upgrade the affected component.
A path traversal vulnerability has been identified in AV Stumpfl Pixera Two Media Server versions prior to 25.2 R3. The issue resides in an unknown function of the component Service Port 1338, leading to arbitrary file read capabilities. Exploitation of this vulnerability allows unauthorized users to read any file on the server, potentially disclosing sensitive information such as system files or registry data that could be leveraged for further attacks.
Users are advised to upgrade to AV Stumpfl Pixera version 25.2 R3, released on October 14, 2025. In this version, Pixera introduced API allow-listing to limit API access, which can help mitigate the vulnerability. Additionally, applying strict IP whitelisting to restrict access to the web panel and API from trusted sources is recommended.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 3, 2026CISA-ADP
Assessed May 4, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gist.github.com/TrebledJ/585a20525e45549f299d282233632608 | [email protected] | BundleExploitRemedyTechnical Description |
| https://help.pixera.one/changelogs-version-overviews/pixera-252-overview-changelog | [email protected] | Release NotesVendor |
| https://vuldb.com/submit/805275 | [email protected] | Permission Required |
| https://vuldb.com/vuln/360873 | [email protected] | AdvisoryPermission RequiredRemedy |
| https://vuldb.com/vuln/360873/cti | [email protected] | AdvisoryPermission Required |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| AV Stumpfl Pixera Two Media Server | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 3, 2026 | New CVE Received | [email protected] |
Volerion