ended3월 25일· 1 sources

CVE-2026-33690: CVE-2026-33690: IP Address Spoofing via Unsafe Header Processing in WWBN AVideo

CVE-2026-33690: WWBN AVideo의 안전하지 않은 헤더 처리를 통한 IP 주소 스푸핑 취약점

Why it matters

WWBN AVideo versions up to 26.0 are vulnerable to IP address spoofing (CVE-2026-33690, CVSS 5.3) due to blindly trusting user-controlled HTTP headers like X-Forwarded-For for client IP resolution. This allows attackers to bypass IP-based access controls. The issue is fixed in version 26.1 via commit 1a1df6a, which implements a conditional trust model based on private IP ranges.

1
Sources
+0
24h
Growth
180d
Active
CVE-2026-33690WWBN AVideoIP SpoofingX-Forwarded-ForCWE-348Access Control Bypass

Sources

Related Issues