SECURITY RESEARCH Player PoC: stream plays from Munowatch CDN with no valid subscription. Server-side entitlement not enforced.
SECURITY PoC — NO AUTH
This movie's CDN stream is playing without login or subscription
Playback

Return to Paradise 17 Episodes (67 of 67)

EP 1Return to ParadiseEP 2Return to Paradise 2EP 3Return to Paradise 3EP 4Return to Paradise 4EP 5Return to Paradise 5EP 6Return to Paradise 6EP 7Return to Paradise 7EP 8Return to Paradise 8EP 9Return to Paradise 9EP 10Return to Paradise 10EP 11Return to Paradise 11EP 12Return to Paradise 12EP 13Return to Paradise 13EP 14Return to Paradise 14EP 15Return to Paradise 15EP 16Return to Paradise 16EP 17Return to Paradise 17EP 18Return to Paradise 18EP 19Return to Paradise 19EP 20Return to Paradise 20EP 21Return to Paradise 21EP 22Return to Paradise 22EP 23Return to Paradise 23EP 24Return to Paradise 24EP 25Return to Paradise 25EP 26Return to Paradise 26EP 27Return to Paradise 27EP 28Return to Paradise 28EP 29Return to Paradise 29EP 30Return to Paradise 30EP 31Return to Paradise 31EP 32Return to Paradise 32EP 33Return to Paradise 33EP 34Return to Paradise 34EP 35Return to Paradise 35EP 36Return to Paradise 36EP 37Return to Paradise 37EP 38Return to Paradise 38EP 39Return to Paradise 39EP 40Return to Paradise 40EP 41Return to Paradise 41EP 42Return to Paradise 42EP 43Return to Paradise 43EP 44Return to Paradise 44EP 45Return to Paradise 45EP 46Return to Paradise 46EP 47Return to Paradise 47EP 48Return to Paradise 48EP 49Return to Paradise 49EP 50Return to Paradise 50EP 51Return to Paradise 51EP 52Return to Paradise 52EP 53Return to Paradise 53EP 54Return to Paradise 54EP 55Return to Paradise 55EP 56Return to Paradise 56EP 57Return to Paradise 57EP 58Return to Paradise 58EP 59Return to Paradise 59EP 60Return to Paradise 60EP 61Return to Paradise 61EP 62Return to Paradise 62EP 63Return to Paradise 63EP 64Return to Paradise 64EP 65Return to Paradise 65EP 66Return to Paradise 66EP 67Return to Paradise 67
Per-movie CDN bypass proof The API returned playingUrl for Return to Paradise 17 with issubscriber: false, user_access: deny, and paid_for: true. The video_name + serverhost from the API response are used to construct the CDN URL above, confirming that the file for this specific movie is publicly accessible with no authentication.
Security research evidence Inspect entitlement results, CDN URLs, and the raw API response Access control failed
API response evidence
Endpoint called GET /api/preview/v2/63364/0
User ID used 0 (no user / not logged in)
JWT used Expired Feb 2024 (extracted from APK)
issubscriber false
user_access
paid_for YES (premium content)
substatus EXPIRED
serverhost 47
video_name 17.Return to Paradise.-..VJ.Ashim.mp4
playingUrl returned YES — URL in response
API playingUrl value https://munowatch.co/clips/ELI.mp4
CDN stream https://munotek-vault.b-cdn.net/stw42/fya/17.Return%20to%20Paradise.-..VJ.Ashim.mp4

Finding: The server sets user_access=deny and issubscriber=false but still returns playingUrl in the same response. Subscription is enforced client-side only — any caller with the expired APK JWT can obtain stream URLs without a subscription. Munowatch CDN (b-cdn.net) serves content with no auth required (direct HTTP Range requests succeed with HTTP 206).