Impact
An unauthenticated arbitrary file write flaw allows attackers to write up to 4 GB of content to the filesystem through HTTP PUT requests against the aVideoEncoderChunk.json.php endpoint. The weakness, classified as CWE‑306, permits the creation or overwriting of arbitrary files, which can exhaust disk space, corrupt the video encoding process, or serve as a stepping stone to local file inclusion attacks that may lead to remote code execution.
Affected Systems
The vulnerability affects the WWBN AVideo platform across a range of releases, specifically versions 14.2, 14.3, 14.3.1, 14.4, 18.0, 21.0, 22.0, 24.0, 25.0, 26.0, and 29.0. All CPE entries for these versions are impacted.
Risk and Exploitability
With a CVSS score of 6.9 and no EPSS data, the potential for exploitation remains high in environments where the endpoint is publicly reachable. The flaw is accessed via an unauthenticated HTTP PUT request; because authentication is not required, attackers can readily submit payloads. Successful exploitation can cause denial of service by filling disk space, degrade service functionality, or, if combined with local file inclusion, enable remote code execution. The vulnerability is not listed in CISA’s KEV catalog, but the lack of a defensive barrier makes it a credible threat.
OpenCVE Enrichment