Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-84479— WWBN AVideo Authentication Bypass via User-Agent Header

Quick assessment

Affected
WWBN AVideo
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

WWBN AVideo(当前版本 e01e41ecc 及更早版本)在登录过程中有三个安全控制措施仅依赖于客户端提供的 User-Agent 请求头。 和 函数通过检查 是否与硬编码的字面量("AVideoEncoder" / "AVideoMobileApp")相匹配来进行判断,既没有进行 IP 检查,也没有使用共享密钥。攻击者在提交有效凭证并将 设置为 后,可以绕过双因素认证(2FA),跳过暴力破解触发的验证码升级机制,并避免在登录/设备审计历史中被记录。在公告发布时,尚未提供相关补丁。

CVSS 9.1 · Critical
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-84479

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
WWBN AVideo Authentication Bypass via User-Agent Header
Source: CVE Program / CVE List V5
Vulnerability Description
WWBN AVideo (current e01e41ecc and earlier) makes three login-time security controls depend solely on the client-supplied User-Agent header. The isAVideoEncoder()/isAVideoMobileApp() checks match HTTP_USER_AGENT against a hardcoded literal ("AVideoEncoder"/"AVideoMobileApp") with no IP check or shared secret. An attacker who submits valid credentials and sets User-Agent: AVideoEncoder bypasses two-factor authentication, skips brute-force captcha escalation, and avoids being recorded in the login/device audit history. No patch is available at the time of publication.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
使用欺骗进行的认证绕过
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
WWBN AVideo 0 ~ 29.0 -

II. Public POCs for CVE-2026-84479

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-84479

登录查看更多情报信息。

Other References for CVE-2026-84479 (2)

Same Patch Batch · WWBN · 2026-09-01 · 11 CVEs total

CVE-2026-84480 9.8 CRITICAL WWBN AVideo Password Recovery Token Expiration Bypass
CVE-2026-84482 8.8 HIGH WWBN AVideo Cross-Site Request Forgery via get_domain() validation
CVE-2026-84187 8.2 HIGH AVideo on_publish.php Missing Authentication Check via RTMP Callback
CVE-2026-83595 8.1 HIGH AVideo Cross-Site Request Forgery via plugin/API/set.json.php
CVE-2026-84208 7.5 HIGH AVideo User_Location Plugin Unauthenticated SQL Injection
CVE-2026-84476 7.5 HIGH WWBN AVideo Authentication Bypass via X-Real-IP Header
CVE-2026-84478 7.3 HIGH WWBN AVideo Unauthenticated Arbitrary Log File Deletion
CVE-2026-84481 6.9 MEDIUM WWBN AVideo through 30.0 Information Disclosure via MobileManager
CVE-2026-84477 5.4 MEDIUM AVideo Stored XSS via Live Schedule Title Description
CVE-2026-84483 5.3 MEDIUM WWBN AVideo Unauthenticated Password Hash Oracle via encryptPass.json.php

IV. Related Vulnerabilities

V. Comments for CVE-2026-84479

No comments yet


Leave a comment