Vulnerability Description
WWBN AVideo through 30.0 contains an information disclosure vulnerability in the MobileManager plugin getConfiguration endpoint that returns sensitive configuration data to unauthenticated visitors. Attackers can send an unauthenticated GET request to plugin/MobileManager/getConfiguration.json.php to obtain TLS private key file paths, socket configuration details, platform version, and debug flags enabling further targeted attacks.
Related Weaknesses (CWE)
References
- https://github.com/WWBN/AVideo/security/advisories/GHSA-5jfh-mcm7-299m
- https://www.vulncheck.com/advisories/wwbn-avideo-through-30.0-information-disclo
- https://github.com/WWBN/AVideo/security/advisories/GHSA-5jfh-mcm7-299m
FAQ
What is CVE-2026-84481?
CVE-2026-84481 is a documented vulnerability. WWBN AVideo through 30.0 contains an information disclosure vulnerability in the MobileManager plugin getConfiguration endpoint that returns sensitive configuration data to unauthenticated visitors. A...
How severe is CVE-2026-84481?
CVSS scoring is not yet available for CVE-2026-84481. Check NVD for updates.
Is there a patch for CVE-2026-84481?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.