Server-side Request Forgery Vulnerability in WWBN AVideo
CVE-2026-82648

7.1HIGH

Key Information:

Vendor

Wwbn

Status
Vendor
CVE Published:
30 August 2026

What is CVE-2026-82648?

The WWBN AVideo platform contains a vulnerability in the isSSRFSafeURL function that allows attackers to bypass existing server-side request forgery (SSRF) protections. This failure occurs due to the inability of the system to properly normalize NAT64 addresses provided in hexadecimal format. Attackers can exploit this oversight by supplying hex-encoded NAT64 addresses, such as 64:ff9b::a9fe:a9fe, which can allow unauthorized access to cloud metadata services and loopback interfaces, posing a significant security risk.

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

rajivraj
.