Impact
WWBN AVideo does not validate trusted proxies before accepting the X-Real-IP and X-Forwarded-For HTTP headers. The missing proxy validation allows an attacker to spoof the client address that the enforceRateLimit() function uses, enabling unlimited credential guessing. This flaw is a classic authentication bypass and is classified as CWE-290. Attackers can rotate the header on every request to avoid rate limiting, leading to a brute‑force attack surface that can compromise user accounts.
Affected Systems
The vulnerability affects the WWBN:AVideo product. No specific version information is listed, so all deployed instances should be considered potentially impacted until a patch is confirmed to apply to the target environment.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity, and while no EPSS score is available, the vulnerability is not yet present in the CISA KEV catalog. The likely attack vector is remote: an attacker can send regular HTTP requests with a crafted X‑Real‑IP header to bypass rate limits. Proper proxy validation and application of the vendor patch are required to mitigate the risk.
OpenCVE Enrichment