Path Traversal Vulnerability in WWBN AVideo API
CVE-2026-84478
6.9MEDIUM
What is CVE-2026-84478?
The AVideo product by WWBN contains a path traversal vulnerability in the get_api_login_code endpoint of its API. This flaw allows unauthenticated attackers to exploit directory traversal sequences, leading to the unauthorized deletion of arbitrary .log files. Such an exploit can result in significant disruption, as attackers can use it to obliterate crucial audit logs while also probing the server's filesystem for sensitive information. This vulnerability poses a serious risk to data integrity and confidentiality, highlighting the importance of securing API endpoints against unauthorized access.
Affected Version(s)
AVideo 0 <= 29.0
