CyberRota Analysis
AI-GeneratedThe MobileManager plugin in WWBN AVideo versions up to 30.0 is vulnerable to information disclosure, allowing unauthenticated users to access sensitive configuration data through the getConfiguration endpoint. This exposure can reveal TLS private key file paths and other critical details, potentially facilitating further targeted attacks. Organizations using this plugin should prioritize patching to mitigate the risk of unauthorized access to sensitive information.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
WWBN AVideo through 30.0 contains an information disclosure vulnerability in the MobileManager plugin getConfiguration endpoint that returns sensitive configuration data to unauthenticated visitors. Attackers can send an unauthenticated GET request to plugin/MobileManager/getConfiguration.json.php to obtain TLS private key file paths, socket configuration details, platform version, and debug flags enabling further targeted attacks.