CVE-2026-30280

An arbitrary file overwrite vulnerability in RAREPROB SOLUTIONS PRIVATE LIMITED Video player Play All Videos v1.0.135 allows attackers to overwrite critical internal files via the file import process, leading to arbtrary code execution or information exposure.
References
Link Resource
https://github.com/Secsys-FDU/AF_CVEs/issues/29 Exploit Third Party Advisory Issue Tracking
https://rareprob-website.firebaseapp.com/ Product
https://secsys.fudan.edu.cn/ Not Applicable
Configurations

Configuration 1 (hide)

cpe:2.3:a:rareprob:video_player:1.0.135:*:*:*:*:android:*:*

History

02 Apr 2026, 20:44

Type Values Removed Values Added
First Time Rareprob video Player
Rareprob
CPE cpe:2.3:a:rareprob:video_player:1.0.135:*:*:*:*:android:*:*
References () https://github.com/Secsys-FDU/AF_CVEs/issues/29 - () https://github.com/Secsys-FDU/AF_CVEs/issues/29 - Exploit, Third Party Advisory, Issue Tracking
References () https://rareprob-website.firebaseapp.com/ - () https://rareprob-website.firebaseapp.com/ - Product
References () https://secsys.fudan.edu.cn/ - () https://secsys.fudan.edu.cn/ - Not Applicable

01 Apr 2026, 16:23

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
CWE CWE-434

31 Mar 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-31 20:16

Updated : 2026-04-02 20:44


NVD link : CVE-2026-30280

Mitre link : CVE-2026-30280

CVE.ORG link : CVE-2026-30280


JSON object : View

Products Affected

rareprob

  • video_player
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type