CVE-2026-3966

MEDIUM

wvp-GB28181-pro <= 2.7.4-20260107 - Server-Side Request Forgery via MediaServer.streamIp

Title source: manual
STIX 2.1

Description

A vulnerability was detected in 648540858 wvp-GB28181-pro up to 2.7.4-20260107. Affected by this vulnerability is the function getDownloadFilePath of the file /src/main/java/com/genersoft/iot/vmp/media/abl/ABLMediaNodeServerService.java of the component IP Address Handler. The manipulation of the argument MediaServer.streamIp results in server-side request forgery. The attack may be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

References (4)

Core 4
Core References
Permissions Required, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.350395
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.350395
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.768915
Issue Tracking exploit issue-tracking
https://github.com/AnalogyC0de/public_exp/issues/15

Scores

CVSS v3 6.3
EPSS 0.0021
EPSS Percentile 10.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-918
Status published
Products (1)
648540858/wvp-GB28181-pro 2.7.4-20260107
Published Mar 12, 2026
Tracked Since Mar 12, 2026