CVE-2026-3966
Last modified
CVE-2026-3966 is a medium-severity vulnerability rated 6.3/10 on the CVSS scale. A vulnerability was detected in 648540858 wvp-GB28181-pro up to 2.7.4-20260107. Affected by this vulnerability is the function getDownloadFilePath of the file /src/main/java/com/genersoft/iot/vmp/media/abl/ABLMediaNodeServerService.java of the component IP Address Handler. EPSS estimates a 0.21% chance of exploitation in the next 30 days.
Description
A vulnerability was detected in 648540858 wvp-GB28181-pro up to 2.7.4-20260107. Affected by this vulnerability is the function getDownloadFilePath of the file /src/main/java/com/genersoft/iot/vmp/media/abl/ABLMediaNodeServerService.java of the component IP Address Handler. The manipulation of the argument MediaServer.streamIp results in server-side request forgery. The attack may be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-3966?
How severe is CVE-2026-3966?
How do I fix CVE-2026-3966?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-39654Improper Neutralization of Input During Web Page Generation …5.9
- CVE-2026-39655Missing Authorization vulnerability in TeconceTheme Mayosis …5.3
- CVE-2026-39656Missing Authorization vulnerability in Razorpay Razorpay for…5.3
- CVE-2026-39657Missing Authorization vulnerability in leadlovers leadlovers…5.3
- CVE-2026-39658Missing Authorization vulnerability in Coding Panda Panda Po…5.3
- CVE-2026-39659Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-39660Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-39661Improper Control of Filename for Include/Require Statement i…7.5
- CVE-2026-39662Missing Authorization vulnerability in ProWCPlugins Product …5.3
- CVE-2026-39663Missing Authorization vulnerability in themetechmount TrueBo…5.3
- CVE-2026-39664Missing Authorization vulnerability in leadrebel Leadrebel l…5.3
- CVE-2026-39665Improper Neutralization of Input During Web Page Generation …6.5
Are you affected by CVE-2026-3966?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
