Summary
CVE-2026-84476 is an authentication bypass vulnerability (CWE-290) in WWBN AVideo. The application’s login rate-limiting function trusts client IP addresses taken from the X-Real-IP and X-Forwarded-For headers without verifying that the request actually passed through a trusted proxy, allowing an unauthenticated network attacker to spoof their apparent source address. This lets an attacker bypass login throttling and perform unlimited credential-guessing attacks, and the issue is rated 8.7 (CVSS v4.0).
Technical details
- Root cause: AVideo’s
enforceRateLimit()function derives the client identity used for throttling from theX-Real-IPandX-Forwarded-ForHTTP headers, without validating that the request originated from a trusted proxy. - Trigger condition: An attacker sends login requests while rotating the value of these headers, causing each request to appear to originate from a different client.
- Attack vector: Network, no authentication or user interaction required.
- Impact: Login rate limiting is rendered ineffective, enabling unlimited/unthrottled password-guessing (brute-force) attempts against user accounts.
Affected software
- WWBN AVideo, versions 0 through 29.0
Severity
- CVSS v4.0: 8.7 (High) —
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N - CVSS v3.1: 7.5 (High) —
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Mitigation and recommended actions
- Immediate: Upgrade WWBN AVideo to a version beyond 29.0 that validates trusted proxies before honoring
X-Real-IP/X-Forwarded-Forheaders in the rate-limiting logic. - If patching is not immediately possible: terminate/normalize client IP at a trusted reverse proxy or load balancer and strip or override client-supplied
X-Real-IP/X-Forwarded-Forheaders before they reach the application; enforce account lockout or MFA independent of IP-based rate limiting; monitor authentication logs for high-volume login attempts with varying forwarded-IP headers.
How IONIX identifies potentially affected assets
IONIX matches the following signals against data already collected when it crawled the asset; identifying the technology sends no request beyond that crawl.
- Page title:
Sign In - AVideo,AVideo - Raw response body:
id="avideoModal",avideoAlert(,avideoModalIframe(

