SECURITY RESEARCH Player PoC: stream plays from Munowatch CDN with no valid subscription. Server-side entitlement not enforced.
SECURITY PoC — NO AUTH
This movie's CDN stream is playing without login or subscription
Playback
Per-movie CDN bypass proof The API returned playingUrl for Love in the Moonlight 7 with issubscriber: false, user_access: deny, and paid_for: true. The video_name + serverhost from the API response are used to construct the CDN URL above, confirming that the file for this specific movie is publicly accessible with no authentication.
Security research evidence Inspect entitlement results, CDN URLs, and the raw API response Access control failed
API response evidence
Endpoint called GET /api/preview/v2/63709/0
User ID used 0 (no user / not logged in)
JWT used Expired Feb 2024 (extracted from APK)
issubscriber false
user_access deny
paid_for YES (premium content)
substatus EXPIRED
serverhost 76
video_name Love in the Moonlight_ENG_Sub_E07.mp4
playingUrl returned YES — URL in response
API playingUrl value https://munowatch.co/clips/ELI.mp4
CDN stream https://munotech2.b-cdn.net/subaru/subaru42/Love%20in%20the%20Moonlight_ENG_Sub_E07.mp4

Finding: The server sets user_access=deny and issubscriber=false but still returns playingUrl in the same response. Subscription is enforced client-side only — any caller with the expired APK JWT can obtain stream URLs without a subscription. Munowatch CDN (b-cdn.net) serves content with no auth required (direct HTTP Range requests succeed with HTTP 206).