#VU125440 Insecure Default Initialization of Resource in AVideo - CVE-2026-33037

 

#VU125440 Insecure Default Initialization of Resource in AVideo - CVE-2026-33037

Published: April 8, 2026


Vulnerability identifier: #VU125440
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2026-33037
CWE-ID: CWE-1188
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
AVideo
Software vendor:
World Wide Broadcast Network

Description

The vulnerability allows a remote attacker to gain administrative access to the application.

The vulnerability exists due to insecure default initialization of resource in the official Docker deployment manifests and automated installer when deploying AVideo without overriding the default admin password. A remote attacker can log in with the predictable default admin credential to gain administrative access to the application.

Exploitation depends on deployments that retain the default SYSTEM_ADMIN_PASSWORD value during installation.


Remediation

Install security update from vendor's website.

External links