VYPR

Streamermax Mk Ii Firmware

by Axeltechnology

CVEs (1)

  • CVE-2025-63223CriNov 19, 2025
    risk 0.64cvss 9.8epss 0.01

    The Axel Technology StreamerMAX MK II devices (firmware versions 0.8.5 to 1.0.3) are vulnerable to Broken Access Control due to missing authentication on the /cgi-bin/gstFcgi.fcgi endpoint. Unauthenticated remote attackers can list user accounts, create new administrative users,…