Impact
WWBN AVideo includes a flaw where the video_id_hash credential behaves as a non‑expiring, non‑revocable bearer token. An attacker who obtains a valid video_id_hash can replay it indefinitely to authenticate as the video owner, gaining complete administrative control over the account. The credential remains valid even after the owner changes their password, enabling prolonged compromise. This constitutes an authentication bypass that results in full privilege escalation.
Affected Systems
The vulnerability affects the WWBN AVideo platform. No specific version information is supplied, so all deployments of AVideo are considered potentially vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score is 9.3, indicating critical severity. EPSS data is not available, but the lack of a revocation mechanism suggests that exploitation can occur as long as the token is present. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, accessed through the public web interface of AVideo. An attacker can obtain a video_id_hash by exploiting other weaknesses or through social engineering, then use it to authenticate as any owner whose token remains active.
OpenCVE Enrichment