CVE-2026-82648: Wwbn Avideo
High severity, CVSS 7.1. EPSS: 0.3% chance of exploitation in the next 30 days.
WWBN AVideo contains a server-side request forgery filter bypass vulnerability in the isSSRFSafeURL function that fails to normalize NAT64 addresses written in hexadecimal form. Attackers can bypass SSRF protections by supplying hex-encoded NAT64 addresses like 64:ff9b::a9fe:a9fe to reach cloud metadata services and loopback interfaces.
Affected products
- Wwbn Avideo
Published 2026-08-30. Last modified 2026-09-02.