Impact
A vulnerable AVideo API exempts requests that contain a bot User‑Agent header from its rate‑limit mechanism, allowing attackers to send an unlimited number of requests to protected endpoints. This bypass enables brute‑force attempts on login and other eight operations, compromising accounts from a single IP address. The flaw reflects inappropriate authentication‑attempt restrictions (CWE‑307).
Affected Systems
The affected platform is AVideo by WWBN. No specific release numbers are listed in the advisory, so all builds containing the documented API are potentially affected until the vendor issues a patch.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.3, indicating moderate severity. No EPSS score is available, so exploitation likelihood is not precisely quantified, but the ability to bypass rate limits from any IP source makes it attractive to attackers. The flaw is not currently listed in the CISA KEV catalog. Exploitation is straightforward: an attacker simply sends HTTP requests with a bot User‑Agent header, repeatedly invoking the protected API endpoints and evading rate limits to conduct unlimited password‑guessing attempts.
OpenCVE Enrichment