Description
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a server-side request forgery vulnerability in the _json_decode function that fetches remote URLs and local file paths without SSRF validation. Unauthenticated attackers can POST file paths or HTTP URLs to login.json.php to read local files or access internal services, with results parsed as login credentials.
Published: 2026-09-11
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch
AI Analysis

Impact

WWBN AVideo contains an SSRF vulnerability in the _json_decode function used by login.json.php. The function accepts arbitrary file paths or HTTP URLs without performing SSRF validation and returns the retrieved content parsed as login credentials. An attacker can exploit this by sending, causing the server to read local files or reach internal services and disclose the data in the response. This exposes sensitive configuration or credential information and can serve as a foothold for further compromise.

Affected Systems

The vulnerability affects the WWBN AVideo application. No specific affected versions are listed in the vulnerable until a fix is applied.

Risk and Exploitability

The CVSS score of 6.9 indicates a medium severity vulnerability. The exploitation can be performed without authentication by sending a carefully crafted POST request to login.json.php, making the threat vector broadly reachable. Although the EPSS score is not available and the vulnerability is not listed in KEV, the lack of input validation means an unauthenticated attacker can read local files or internal service responses, potentially exposing critical data. The risk is moderate, with a realistic chance of exploitation in environments where the application server can reach internal networks.

Generated by OpenCVE AI on September 11, 2026 at 14:08 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest AVideo update released by WWBN that addresses the SSRF flaw.
  • If an update is unavailable, either disable the login.json.php endpoint or restrict it so that only authenticated users can invoke it.
  • Implement network segmentation or firewall rules to block the application server from accessing internal services and local file paths used by the vulnerable endpoint.

Generated by OpenCVE AI on September 11, 2026 at 14:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Description WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a server-side request forgery vulnerability in the _json_decode function that fetches remote URLs and local file paths without SSRF validation. Unauthenticated attackers can POST file paths or HTTP URLs to login.json.php to read local files or access internal services, with results parsed as login credentials.
Title WWBN AVideo Unauthenticated SSRF via login.json.php
First Time appeared Wwbn
Wwbn avideo
Weaknesses CWE-918
CPEs cpe:2.3:a:wwbn:avideo:-:*:*:*:*:*:*:*
Vendors & Products Wwbn
Wwbn avideo
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-15T16:10:23.552Z

Reserved: 2026-09-11T10:51:31.662Z

Link: CVE-2026-89242

cve-icon Vulnrichment

Updated: 2026-09-15T16:10:18.843Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T12:16:53.803

Modified: 2026-09-15T17:17:34.187

Link: CVE-2026-89242

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T16:45:14Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)