Impact
A race condition in AVideo’s enforceRateLimit function allows attackers to increment rate‑limit counters non‑atomically, making each concurrent request add only a single counter value instead of the intended atomic increment. This flaw lets attackers bypass the documented 30‑attempt‑per‑5‑minute login limit, enabling rapid credential guessing attempts. The weakness corresponds to CWE‑307, reflecting a failure to enforce proper authentication rate controls.
Affected Systems
The vulnerability affects the WWBN AVideo application up through version 29.0. Any installation of AVideo before the release that includes the enforceRateLimit implementation is susceptible until updated to a patched version.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity, and the EPSS score of less than 1% suggests a low likelihood of widespread exploitation at present. The flaw is not listed in the CISA KEV catalog, meaning no publicly known exploits have been documented. Based on the description, the likely attack vector is web‑based, with an attacker issuing multiple simultaneous login requests to exhaust or bypass the rate limiter. If successful, the attacker could gain unauthorized access to user accounts, posing a confidentiality risk.
OpenCVE Enrichment