#VU125473 Missing Authentication for Critical Function in AVideo - CVE-2026-33719
Published: April 8, 2026
AVideo
World Wide Broadcast Network
Description
The vulnerability allows a remote attacker to modify CDN configuration and cause a denial of service.
The vulnerability exists due to missing authentication for critical function in plugin/CDN/status.json.php and plugin/CDN/disable.json.php when handling requests with an unconfigured default key. A remote attacker can send specially crafted requests with attacker-controlled par parameters to modify CDN configuration and cause a denial of service.
Exploitation is possible only when the CDN plugin is enabled and its key remains in the default empty state.