Impact
The vulnerability lies in AVideo's isSSRFSafeURL function, which fails to strip embedded IPv4 addresses from NAT64, 6to4, and Teredo IPv6 transition formats. This omission allows attackers to encode private IPv4 targets inside transition addresses and exploit the LiveLinks proxy endpoint, which is publicly accessible and requires no authentication. The result is a traditional SSRF that can reach internal services, cloud metadata endpoints, and any other host reachable from the server, exposing sensitive internal data and enabling further lateral movement.
Affected Systems
All installations of AVideo version 23.x or earlier are affected. The vulnerability was present in code prior to the 24.0 release and has been fixed in the latest version released by WWBN.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate to high severity. No EPSS score is available, and the vulnerability is not listed in CISA’s KEV catalog. Because the LiveLinks endpoint is unauthenticated and reachable from the external network, the attack vector is remote over the Internet with minimal prerequisites. Once exploited, the attacker can consume internal network resources, access internal metadata services, and potentially pivot further into the infrastructure.
OpenCVE Enrichment