#VU125473 Missing Authentication for Critical Function in AVideo - CVE-2026-33719

 

#VU125473 Missing Authentication for Critical Function in AVideo - CVE-2026-33719

Published: April 8, 2026


Vulnerability identifier: #VU125473
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2026-33719
CWE-ID: CWE-306
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
AVideo
Software vendor:
World Wide Broadcast Network

Description

The vulnerability allows a remote attacker to modify CDN configuration and cause a denial of service.

The vulnerability exists due to missing authentication for critical function in plugin/CDN/status.json.php and plugin/CDN/disable.json.php when handling requests with an unconfigured default key. A remote attacker can send specially crafted requests with attacker-controlled par parameters to modify CDN configuration and cause a denial of service.

Exploitation is possible only when the CDN plugin is enabled and its key remains in the default empty state.


Remediation

Install security update from vendor's website.

External links