PT-2026-94235 · Avideo · Avideo
CVSS v4.0
8.3
High
| Vector | AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
AVideo versions prior to c3edcc274c389816d434acadac07ee78eaf330c1
Description
The software uses cryptographically weak
uniqid() values for RTMP publish keys in LiveTransmition. This reduces key entropy to approximately one million possibilities per second of creation. An attacker with knowledge of the channel creation time can brute-force the five-digit microsecond component to forge valid stream keys and broadcast content as the channel owner.Recommendations
Update AVideo to a version later than c3edcc274c389816d434acadac07ee78eaf330c1.
Exploit
Fix
Use of Insufficiently Random Values
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Avideo