Improper Input Validation Vulnerability in Pexip Infinity by Pexip
CVE-2025-49088

5.9MEDIUM

Key Information:

Vendor

Pexip

Status
Vendor
CVE Published:
25 December 2025

What is CVE-2025-49088?

Pexip Infinity versions 32.0 through 37.1, in certain configurations of the One Touch Join (OTJ) for Teams SIP Guest Join, exhibit an improper input validation vulnerability. This flaw allows remote attackers to craft malicious calendar invites that can trigger a software abort, ultimately resulting in a denial of service. Users are encouraged to upgrade to version 37.2 or later to mitigate this issue.

Affected Version(s)

Infinity 32.0 < 37.2

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-49088 : Improper Input Validation Vulnerability in Pexip Infinity by Pexip