CVE-2026-82648: WWBN AVideo SSRF Filter Bypass via NAT64 Hex Address
Published Aug 30, 2026
·Updated
WWBN AVideo contains a server-side request forgery filter bypass vulnerability in the isSSRFSafeURL function that fails to normalize NAT64 addresses written in hexadecimal form. Attackers can bypass SSRF protections by supplying hex-encoded NAT64 addresses like 64:ff9b::a9fe:a9fe to reach cloud metadata services and loopback interfaces.
Affected Software
1 affected component
WWBN AVideo
Event History
Aug 30, 2026
CVE Published
via MITRE·02:33 PM
Data Sourced
via MITRE·02:33 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Does exploitation require authentication or user interaction?
The CVSS vector indicates network-based exploitation with low privileges required and no user interaction. It also rates attack complexity as high.
2
What impact does the CVSS vector indicate?
The vector indicates high confidentiality impact, low integrity impact, and no availability impact. It also indicates a scope change.