Description
WWBN AVideo contains a server-side request forgery filter bypass vulnerability in the isSSRFSafeURL function that fails to normalize NAT64 addresses written in hexadecimal form. Attackers can bypass SSRF protections by supplying hex-encoded NAT64 addresses like 64:ff9b::a9fe:a9fe to reach cloud metadata services and loopback interfaces.
Published: 2026-08-30
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

WWBN AVideo contains a server‑side request forgery filter bypass in the isSSRFSafeURL function. The function does not normalize NAT64 addresses expressed in hexadecimal form, allowing attackers to craft URLs such as 64:ff9b::a9fe:a9fe that resolve to internal loopback or cloud metadata services. This bypass lets an attacker reach privileged internal endpoints that should be protected, potentially exposing sensitive configuration data or enabling further compromise.

Affected Systems

The vulnerability affects the WWBN AVideo application. No specific version numbers are listed, so all installations should be reviewed.

Risk and Exploitability

The CVSS score of 7.1 indicates High severity. With no EPSS data available, the likelihood of exploitation depends on deployment exposure, but the bypass is functional via a simple HTTP request. The vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known exploits yet, but the attack vector is feasible for remote attackers with access to the application’s request handling.

Generated by OpenCVE AI on August 30, 2026 at 15:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update AVideo to the latest release where the SSRF filter correctly normalizes hex‑encoded NAT64 addresses.
  • If a patch is not immediately available, configure the application to disallow outbound requests to loopback addresses and cloud metadata service IP ranges.
  • Implement network-level controls such as firewall rules or proxy restrictions to block outbound traffic to internal IP ranges and known metadata endpoints.

Generated by OpenCVE AI on August 30, 2026 at 15:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 30 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
Description WWBN AVideo contains a server-side request forgery filter bypass vulnerability in the isSSRFSafeURL function that fails to normalize NAT64 addresses written in hexadecimal form. Attackers can bypass SSRF protections by supplying hex-encoded NAT64 addresses like 64:ff9b::a9fe:a9fe to reach cloud metadata services and loopback interfaces.
Title WWBN AVideo SSRF Filter Bypass via NAT64 Hex Address
First Time appeared Wwbn
Wwbn avideo
Weaknesses CWE-20
CPEs cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:*
Vendors & Products Wwbn
Wwbn avideo
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-30T14:33:31.044Z

Reserved: 2026-08-30T13:38:00.101Z

Link: CVE-2026-82648

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-30T15:16:45.300

Modified: 2026-08-30T15:16:45.300

Link: CVE-2026-82648

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-30T15:30:18Z

Weaknesses
  • CWE-20

    Improper Input Validation