---
id: CVE-2026-84481
title: >-
  WWBN AVideo through 30.0 contains an information disclosure vulnerability in
  the MobileManager plugin getConfiguration endpoint that returns sensitive
  configuration data to unauthenticated visitors
summary: >-
  WWBN AVideo through 30.0 contains an information disclosure vulnerability in
  the MobileManager plugin getConfiguration endpoint that returns sensitive
  configuration data to unauthenticated visitors. Attackers can send an
  unauthenticated …
severity: none
cwe:
  - CWE-200
published: '2026-09-01'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T20:18:59.270'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-84481'
references:
  - url: 'https://github.com/WWBN/AVideo/security/advisories/GHSA-5jfh-mcm7-299m'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/wwbn-avideo-through-30.0-information-disclosure-via-mobilemanager
    label: disclosure@vulncheck.com
  - url: 'https://github.com/WWBN/AVideo/security/advisories/GHSA-5jfh-mcm7-299m'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00445
epssPercentile: 0.36042
ingestedAt: '2026-09-08T21:11:12.289Z'
---

## Overview

WWBN AVideo through 30.0 contains an information disclosure vulnerability in the MobileManager plugin getConfiguration endpoint that returns sensitive configuration data to unauthenticated visitors. Attackers can send an unauthenticated GET request to plugin/MobileManager/getConfiguration.json.php to obtain TLS private key file paths, socket configuration details, platform version, and debug flags enabling further targeted attacks.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
