AVideo API fails to enforce rate limits when clients send a bot User-Agent header, allowing attackers to bypass all eight protected operations including login brute-force protection. Attackers can send requests with a bot User-Agent to disable rate limiting and perform unlimited password guessing attempts against any account from a single IP address.
Metrics
Affected Vendors & Products
References
History
Wed, 09 Sep 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 05 Sep 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | AVideo API fails to enforce rate limits when clients send a bot User-Agent header, allowing attackers to bypass all eight protected operations including login brute-force protection. Attackers can send requests with a bot User-Agent to disable rate limiting and perform unlimited password guessing attempts against any account from a single IP address. | |
| Title | AVideo API Rate Limit Bypass via Bot User-Agent Header | |
| First Time appeared |
Wwbn
Wwbn avideo |
|
| Weaknesses | CWE-307 | |
| CPEs | cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Wwbn
Wwbn avideo |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-09-05T12:09:02.729Z
Updated: 2026-09-08T17:20:34.246Z
Reserved: 2026-09-05T11:51:31.101Z
Link: CVE-2026-86186
Updated: 2026-09-08T17:19:11.308Z
Status : Deferred
Published: 2026-09-05T13:18:13.560
Modified: 2026-09-08T20:05:53.177
Link: CVE-2026-86186
No data.