Unauthenticated Arbitrary File Write in AVideo by WWBN
CVE-2026-72748
6.9MEDIUM
What is CVE-2026-72748?
AVideo has a vulnerability in the aVideoEncoderChunk.json.php endpoint that allows remote attackers to exploit an unauthenticated arbitrary file write. By sending HTTP PUT requests, malicious entities can write up to 4 GB of arbitrary content to the server's filesystem. This can lead to denial of service by exhausting disk space, disrupt the video encoding process, or potentially be combined with local file inclusion to enable remote code execution.
Affected Version(s)
AVideo 29.0
