Impact
The vulnerability is a path traversal flaw in the Service Port 1338 element of AV Stumpfl Pixera Two Media Server up to version 25.1 R2. This allows an unauthenticated attacker to potentially read arbitrary files on the host. The flaw is categorized as CWE‑22, a directory traversal weakness, and carries a CVSS score of 5.3, indicating moderate severity. The exploit has been publicly disclosed, meaning threat actors may already be attempting to use it.
Affected Systems
The affected vendor is AV Stumpfl. Product Pixera Two Media Server versions up to 25.1 R2 are impacted, specifically the Service Port 1338 component. The documented fix is to upgrade to 25.2 R3 or later.
Risk and Exploitability
Although the EPSS score is not available, the public disclosure and moderate CVSS suggest attackers could readily exploit this flaw, especially on servers exposed to untrusted networks. The risk is present when the media server is reachable over the Internet or an unsecured internal network; an attacker would send a crafted request over port 1338 to traverse directories and retrieve sensitive files.
OpenCVE Enrichment