CVE-2026-84481

WWBN AVideo through 30.0 contains an information disclosure vulnerability in the MobileManager plugin getConfiguration endpoint that returns sensitive configuration data to unauthenticated visitors. Attackers can send an unauthenticated GET request to plugin/MobileManager/getConfiguration.json.php to obtain TLS private key file paths, socket configuration details, platform version, and debug flags enabling further targeted attacks.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-09-01 23:17

Updated : 2026-09-08 20:18


NVD link : CVE-2026-84481

Mitre link : CVE-2026-84481

CVE.ORG link : CVE-2026-84481


JSON object : View

Products Affected

No product.

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor