#VU125440 Insecure Default Initialization of Resource in AVideo - CVE-2026-33037
Published: April 8, 2026
AVideo
World Wide Broadcast Network
Description
The vulnerability allows a remote attacker to gain administrative access to the application.
The vulnerability exists due to insecure default initialization of resource in the official Docker deployment manifests and automated installer when deploying AVideo without overriding the default admin password. A remote attacker can log in with the predictable default admin credential to gain administrative access to the application.
Exploitation depends on deployments that retain the default SYSTEM_ADMIN_PASSWORD value during installation.