Improper Input Validation in Pexip Infinity Affects Video Communication Solutions
CVE-2025-66443

7.5HIGH

Key Information:

Vendor

Pexip

Status
Vendor
CVE Published:
25 December 2025

What is CVE-2025-66443?

The Pexip Infinity platform, specifically versions 35.0 through 38.1 prior to 39.0, has a vulnerability leading to improper input validation in signaling when using Direct Media for WebRTC. This flaw may enable an attacker to trigger a software abort, which can cause a disruption in service, affecting users' access to the video communication platform. Security measures should be enacted to ensure that systems are updated and configurations are secured to mitigate risks associated with this vulnerability.

Affected Version(s)

Infinity 35.0 < 39.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-66443 : Improper Input Validation in Pexip Infinity Affects Video Communication Solutions