Impact
A server‑side request forgery vulnerability exists in the encoder download‑by‑URL flow when an unpinned retry fallback bypasses DNS pinning validation. An authenticated actor can supply a download URL that redirects to an internal address; the retry path follows the redirect, allowing the server to reach internal resources indirectly and perform blind SSRF attacks. The lack of observable request response feedback makes the attack stealthy, but it can still expose internal data or services.
Affected Systems
All AVideo installations from commit 0dbadbcaaa1b415c7db078a72dc4b26d9fac0485 (inclusive) through the current master branch are vulnerable; the vendor is WWBN and the affected product is AVideo.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS score of less than 1% suggests that exploitation is currently rare. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires authenticated access to trigger the download‑by‑URL flow and a constructed URL that redirects to a target on the internal network. The attack vector, therefore, is an authenticated SSRF. While the risk of a widespread breach is low at present, the blind nature of the attack makes detection difficult, so proactive remediation is recommended.
OpenCVE Enrichment