CVE-2022-32761
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 6.5epss 2.8%
exploitation probability
2.8%top 14% of all CVEs
observed exploitation
nono source reports it
In short
AVideo 11.6 has a flaw that allows attackers to read files from the server by sending specially crafted HTTP requests to the video encoder function. This exposes sensitive information stored on the server.
Technical detail
An information disclosure vulnerability in the aVideoEncoderReceiveImage endpoint allows unauthenticated or low-privileged attackers to read arbitrary files via specially-crafted HTTP requests. The vulnerability affects WWBN AVideo 11.6 and dev master, enabling file enumeration and exfiltration of sensitive data without authentication requirements.
Summary generated and translated by AI from the official description.
An information disclosure vulnerability exists in the aVideoEncoderReceiveImage functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary file read. An attacker can send an HTTP request to trigger this vulnerability.
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Affected products
WWBN · AVideo