Cyber Resilience

CVE-2022-30547

Path Traversal in Wwbn Avideo 11.6

Public PoCHigh EPSSPath Traversal
Published
22 August 2022
Modified
21 November 2024
CVSS Score v3.1 9.9
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS Score 0.64 99.1th percentile
Risk Priority 88 floored blend · peak EPSS

Summary

CVE-2022-30547 is a critical-severity Path Traversal (CWE-22) vulnerability in Wwbn Avideo. Its CVSS base score is 9.9 (Critical).

Operationally, ranked in the top 0.9% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.

The strongest mitigations our analysis identified map to SI-10 (Information Input Validation) and AC-6 (Least Privilege) — see the control section below for these in your framework.

Deeper analysis AI-assisted summary

Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.

A directory traversal vulnerability exists in the unzipDirectory functionality of WWBN AVideo version 11.6 and the development master commit 3f7c0364. Tracked as CVE-2022-30547 and assigned CWE-22, the flaw allows a specially crafted HTTP request to trigger arbitrary command execution. The issue carries a CVSS 3.1 score of 9.9, reflecting network attack vector, low attack complexity, low privileges required, and impacts across confidentiality, integrity, and availability with a scope change.

An authenticated attacker can send a crafted HTTP request to the affected unzipDirectory component and achieve arbitrary command execution on the server. The attack requires no user interaction and can be performed remotely over the network.

Public references include a Talos Intelligence vulnerability report (TALOS-2022-1547) and database update scripts hosted in the AVideo GitHub repository that address version 12.0.

EPSS for the CVE rose from low values after disclosure to a peak of 0.3369 on 2025-12-11 before receding to the current 0.2074, indicating that exploitation interest emerged well after the initial publication.

OWASP Top 10 for Web (2025)

EU & UK References

Vulnerability Data

A directory traversal vulnerability exists in the unzipDirectory functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can send an HTTP request to trigger this vulnerability.

CWE(s)

Related Threats

Likely ATT&CK TechniquesAI

Techniques this vulnerability likely enables, inferred from its description, weakness type, and attributed-actor tradecraft. Confidence is per-technique.

T1190 Exploit Public-Facing Application Initial Accessconfidence: HIGH
Directory traversal in unzipDirectory allows remote authenticated attackers to achieve arbitrary command execution via crafted HTTP requests.
T1059 Command and Scripting Interpreter Executionconfidence: MEDIUM
Arbitrary command execution on the server is enabled by the vulnerability.
inferred from description + CWE · MITRE ATT&CK Enterprise v19.0

CVEs Like This One

CVE-2026-45731Same product: Wwbn Avideo
CVE-2026-41058Same product: Wwbn Avideo
CVE-2026-33293Same product: Wwbn Avideo
CVE-2026-33681Same product: Wwbn Avideo
CVE-2026-41062Same product: Wwbn Avideo
CVE-2026-46337Same product: Wwbn Avideo
CVE-2026-40909Same product: Wwbn Avideo
CVE-2026-33493Same product: Wwbn Avideo
CVE-2026-33238Same product: Wwbn Avideo
CVE-2026-39369Same product: Wwbn Avideo

Affected Assets

wwbn
avideo
11.6

Mitigating Controls

Control response

Prevent
Stop it (NIST 800-53)
  • SI-10 Information Input Validation
  • AC-6 Least Privilege
  • SI-2 Flaw Remediation
Detect
Catch it (NIST detect / respond)

Harden
Shrink the surface (DISA STIG)

Validate
Prove the fix (OWASP ASVS)
  • V5.3.2

Mitigating Controls (NIST 800-53 r5) AI

prevent

Directly blocks the crafted HTTP request by validating path and filename inputs to unzipDirectory before traversal sequences can be processed.

prevent

Limits the privileges of authenticated users so that even successful traversal cannot result in arbitrary command execution outside the intended scope.

prevent

Requires timely application of the vendor-supplied patches (v12.0 database scripts) that remediate the directory traversal flaw in unzipDirectory.

Mitigating Controls (NIST CSF 2.0) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.

PR.PS-02 partial match
prevents

Patching/maintenance can remediate known path-traversal flaws in deployed software (partial prevention of exploitability) but does nothing to stop the coding defect from being introduced in the first place.

PR.AA-05 none match
prevents

PR.AA-05 defines and reviews access policies but does not address code-level pathname neutralization, so neither direction prevents CWE-22.

Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.

detects

Security testing in development catches path traversal via static/dynamic analysis.

prevents

Secure SDLC mandates input validation and path sanitization that directly prevent path traversal.

prevents

Application security requirements include rules for safe file handling and canonicalization.

prevents

Secure architecture principles require least-privilege file access and directory isolation.

prevents

Secure coding standards explicitly forbid unsafe path construction and mandate safe APIs.

mitigates

Information access restriction limits which files an application may read or write.

References