A vulnerability, which was classified as critical, has been found in WWBN AVideo up to 26.0. Affected is the function isSSRFSafeURL of the component EPG Page. The manipulation leads to server-side request forgery. This vulnerability is documented as CVE-2026-34740. The attack can be initiated remotely.
| Vendor | Product | Versions |
|---|---|---|
| wwbn | avideo | <= 26.0 |
Updated severity to CRITICAL, marked as actively exploited, and added detailed description of the vulnerability.
Initial creation