WWBN AVideo 的 函数中存在一个服务器端请求伪造(SSRF)过滤器绕过漏洞,该函数未能对以十六进制形式书写的 NAT64 地址进行规范化处理。攻击者可以通过提供十六进制编码的 NAT64 地址(例如 )来绕过 SSRF 防护,从而访问云元数据服务和本地回环接口。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82645 | 8.6 HIGH | AVideo Unauthenticated Stream Credential Disclosure via Forgeable Token |
| CVE-2026-82644 | 7.5 HIGH | WWBN AVideo Brute-force Rate Limiting Bypass via Missing User-Agent |
| CVE-2026-82643 | 6.5 MEDIUM | WWBN AVideo Unauthenticated Rate Limit Bypass via preauthorize.json.php |
| CVE-2026-82646 | 6.1 MEDIUM | WWBN AVideo Unauthenticated Reflected XSS via url2Embed.json.php |
| CVE-2026-82647 | 6.1 MEDIUM | WWBN AVideo Cross-Site Request Forgery via sendEmail.json.php |
No comments yet