Insecure Default Initialization of Resource in AVideo - CVE-2026-33037

 

Insecure Default Initialization of Resource in AVideo - CVE-2026-33037

Published: April 8, 2026


Vulnerability identifier: #VU125440
CSH Severity: High
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2026-33037
CWE-ID: CWE-1188
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: World Wide Broadcast Network
Affected software:
AVideo

Detailed vulnerability description

The vulnerability allows a remote attacker to gain administrative access to the application.

The vulnerability exists due to insecure default initialization of resource in the official Docker deployment manifests and automated installer when deploying AVideo without overriding the default admin password. A remote attacker can log in with the predictable default admin credential to gain administrative access to the application.

Exploitation depends on deployments that retain the default SYSTEM_ADMIN_PASSWORD value during installation.


How to mitigate CVE-2026-33037

Install security update from vendor's website.

Sources