CVE-2025-66377
Pexip Infinity Management Node vulnerability analysis and mitigation

Overview

CVE-2025-66377 is a Missing Authentication for Critical Function vulnerability (CWE-306) in Pexip Infinity's product-internal API, affecting all versions before 39.0. An attacker who has already achieved code execution on one node within a Pexip Infinity installation can exploit this flaw to impact the operation of other nodes in the same deployment. The vulnerability was published on December 25, 2025, with a patch available in version 39.0. It carries a CVSS v3.1 base score of 7.5 (High) (Pexip Security Bulletins, Red Hat CVE).

Technical details

The root cause is CWE-306 (Missing Authentication for Critical Function): a product-internal API within Pexip Infinity does not enforce authentication, allowing any party with code execution on one node to interact with that API and affect other nodes in the cluster. The attack vector is adjacent network (AV:A), meaning the attacker must already have a foothold — specifically code execution — on at least one node within the Pexip Infinity installation. Attack complexity is rated High (AC:H), reflecting the prerequisite of prior node compromise. No public proof-of-concept exploit code has been identified at this time (Pexip Security Bulletins, Red Hat CVE).

Impact

Successful exploitation allows an attacker who has compromised one node to laterally impact other nodes within the same Pexip Infinity installation, with high confidentiality, integrity, and availability impacts. This could result in disruption of video conferencing services, unauthorized access to call data or media streams, and manipulation of node configurations across the deployment. The scope is limited to the Pexip Infinity installation itself (S:U), but the potential for cross-node compromise makes this a significant risk in multi-node enterprise deployments (Pexip Security Bulletins, Red Hat CVE).

Exploitation steps

  1. Initial Compromise: Gain code execution on at least one node within the target Pexip Infinity installation (e.g., via a separate vulnerability, credential theft, or supply chain attack).
  2. Internal API Discovery: From the compromised node, enumerate internal network interfaces and services to identify the unauthenticated product-internal API endpoint used for inter-node communication.
  3. Unauthenticated API Interaction: Send crafted requests to the identified internal API without providing authentication credentials, leveraging the missing authentication flaw (CWE-306).
  4. Cross-Node Impact: Use the API to disrupt, manipulate, or extract data from other nodes in the Pexip Infinity cluster — potentially affecting call routing, media streams, or node configuration across the entire installation (Pexip Security Bulletins).

Indicators of compromise

  • Network: Unexpected or anomalous API calls between Pexip Infinity nodes, particularly requests lacking authentication headers to internal inter-node API endpoints; unusual lateral traffic patterns between nodes on internal management interfaces.
  • Logs: Pexip Infinity system logs showing unauthenticated access attempts or successful calls to internal API endpoints from unexpected source nodes; error messages or warnings related to inter-node API authentication failures.
  • Process/Behavior: Unexpected changes to node configuration or operational state not initiated by administrators; unexplained disruptions to call routing or media processing on nodes that were not directly administered.

Mitigation and workarounds

Pexip has released version 39.0 of Pexip Infinity, which addresses this vulnerability. Organizations should upgrade all nodes in their Pexip Infinity installation to version 39.0 or later as the primary remediation. As a network-level workaround, restrict access to inter-node management interfaces using firewall rules or network segmentation to limit exposure of internal APIs to trusted nodes only. Monitor for anomalous inter-node API activity as a compensating control until patching is complete (Pexip Security Bulletins).

Community reactions

The vulnerability received coverage from security news aggregators including The Hacker Wire and was noted in CISA's weekly vulnerability bulletin (SB25-363) for the week of December 22, 2025. Social media discussion was limited, with brief mentions on Mastodon and Bluesky by security news accounts. No significant vendor statements beyond the Pexip security bulletin or notable independent researcher commentary have been identified (CISA Bulletin, The Hacker Wire).

Additional resources


SourceThis report was generated using AI

Related Pexip Infinity Management Node vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-59683CRITICAL9.1
  • Pexip Infinity Management Node logoPexip Infinity Management Node
  • cpe:2.3:a:pexip:pexip_infinity
NoYesDec 25, 2025
CVE-2025-66379HIGH7.5
  • Pexip Infinity Management Node logoPexip Infinity Management Node
  • cpe:2.3:a:pexip:pexip_infinity
NoYesDec 25, 2025
CVE-2025-66378HIGH7.5
  • Pexip Infinity Management Node logoPexip Infinity Management Node
  • cpe:2.3:a:pexip:pexip_infinity
NoYesDec 25, 2025
CVE-2025-66377HIGH7.5
  • Pexip Infinity Management Node logoPexip Infinity Management Node
  • cpe:2.3:a:pexip:pexip_infinity
NoYesDec 25, 2025
CVE-2025-66443MEDIUM5.3
  • Pexip Infinity Management Node logoPexip Infinity Management Node
  • cpe:2.3:a:pexip:pexip_infinity
NoYesDec 25, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management