CVE-2026-84481
published 2026-09-01CVE-2026-84481: WWBN AVideo through 30.0 contains an information disclosure vulnerability in the MobileManager plugin getConfiguration endpoint that returns sensitive…
PriorityP342medium6.9CVSS 4.0
AVNACLATNPRNUINVCLVINVANSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.45%
36.6th percentile
WWBN AVideo through 30.0 contains an information disclosure vulnerability in the MobileManager plugin getConfiguration endpoint that returns sensitive configuration data to unauthenticated visitors. Attackers can send an unauthenticated GET request to plugin/MobileManager/getConfiguration.json.php to obtain TLS private key file paths, socket configuration details, platform version, and debug flags enabling further targeted attacks.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| wwbn | avideo | <= 30.0 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
WWBN AVideo up to 30.0 MobileManager Plugin getConfiguration.json.php information disclosure (EUVD-2026-69723)
vuldb·2026-09-02·CVSS 6.9
CVE-2026-84481 [MEDIUM] WWBN AVideo up to 30.0 MobileManager Plugin getConfiguration.json.php information disclosure (EUVD-2026-69723)
A vulnerability described as problematic has been identified in WWBN AVideo up to 30.0. Affected by this issue is some unknown functionality of the file plugin/MobileManager/getConfiguration.json.php of the component MobileManager Plugin. Executing a manipulation can lead to information disclosure.
This vulnerability appears as CVE-2026-84481. The attack may be performed from remote. There is no available exploit.
GHSA
WWBN AVideo through 30.0 contains an information disclosure vulnerability in the MobileManager plugin getConfiguration endpoint that returns sensitive configuration data to unauthenticated visitors.
ghsa_unreviewed·2026-09-02
CVE-2026-84481 [MEDIUM] CWE-200 WWBN AVideo through 30.0 contains an information disclosure vulnerability in the MobileManager plugin getConfiguration endpoint that returns sensitive configuration data to unauthenticated visitors.
WWBN AVideo through 30.0 contains an information disclosure vulnerability in the MobileManager plugin getConfiguration endpoint that returns sensitive configuration data to unauthenticated visitors. Attackers can send an unauthenticated GET request to plugin/MobileManager/getConfiguration.json.php to obtain TLS private key file paths, socket configuration details, platform version, and debug flags enabling further targeted attacks.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-09-01
Published