Path Traversal Vulnerability in WWBN AVideo API
CVE-2026-84478

6.9MEDIUM

Key Information:

Vendor

Wwbn

Status
Vendor
CVE Published:
1 September 2026

What is CVE-2026-84478?

The AVideo product by WWBN contains a path traversal vulnerability in the get_api_login_code endpoint of its API. This flaw allows unauthenticated attackers to exploit directory traversal sequences, leading to the unauthorized deletion of arbitrary .log files. Such an exploit can result in significant disruption, as attackers can use it to obliterate crucial audit logs while also probing the server's filesystem for sensitive information. This vulnerability poses a serious risk to data integrity and confidentiality, highlighting the importance of securing API endpoints against unauthorized access.

Affected Version(s)

AVideo 0 <= 29.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

rajivraj
.