Impact
WWBN AVideo contains a server‑side request forgery filter bypass in the isSSRFSafeURL function. The function does not normalize NAT64 addresses expressed in hexadecimal form, allowing attackers to craft URLs such as 64:ff9b::a9fe:a9fe that resolve to internal loopback or cloud metadata services. This bypass lets an attacker reach privileged internal endpoints that should be protected, potentially exposing sensitive configuration data or enabling further compromise.
Affected Systems
The vulnerability affects the WWBN AVideo application. No specific version numbers are listed, so all installations should be reviewed.
Risk and Exploitability
The CVSS score of 7.1 indicates High severity. With no EPSS data available, the likelihood of exploitation depends on deployment exposure, but the bypass is functional via a simple HTTP request. The vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known exploits yet, but the attack vector is feasible for remote attackers with access to the application’s request handling.
OpenCVE Enrichment