Impact
WWBN AVideo contains a path‑traversal flaw in the get_api_login_code endpoint that permits attackers to delete any .log file on the server. The flaw also allows probing the filesystem to confirm file existence, leading to information disclosure. Because the vulnerability is unauthenticated, any network user can trigger it, compromising audit trails and potentially denying the ability to investigate incidents.
Affected Systems
Vulnerable systems are installations of WWBN AVideo. No specific version data is provided, so any deployment of the product that includes the get_api_login_code API is potentially affected.
Risk and Exploitability
The CVSS score of 6.9 indicates a medium severity risk. No EPSS data is available, and the vulnerability is not listed in the CISA KEV catalog, implying limited known exploitation evidence. The likely attack vector is remote exploitation via the public API, as the endpoint is accessible to unauthenticated users.
OpenCVE Enrichment