Description
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 uses a cryptographically weak pseudo-random number generator when creating account activation / login pairing codes. getRandomCode() in objects/functions.php derives the code entirely from uniqid() (sprintf('%08x%05x', seconds, microseconds)) with a single non-CSPRNG rand() character used only as padding, reducing the code space to roughly 36 x 10^6 (~2^25) values for a known generation second. Because plugin/API/set.json.php?APIName=login_code can be called without authentication, it also serves as an oracle for the server's exact microtime. An unauthenticated remote attacker who guesses a valid, unexpired code (codes expire after 10 minutes) can redeem it at plugin/API/get.json.php?APIName=login_code to obtain the target account's email address and a User::getUserHash(users_id, '+1 year') value, a credential accepted in place of the account password for one year, resulting in account takeover. No patched version is available.
Published: 2026-09-17
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Account takeover via authentication bypass
Action: Restrict API
AI Analysis

Impact

AVideo's activation code generation relies on a cryptographically weak pseudo‑random number generator, deriving the code from the server’s timestamp and a single non‑cryptographic random character, resulting in an effective code space of roughly 36×10⁶ (about 2²⁵) distinct values for a known second. The endpoint plugin/API/set.json.php?APIName=login_code is callable without authentication, serving as an oracle that reveals the exact server microtime. An unauthenticated remote attacker who guesses a valid, unexpired code within the ten‑minute validity window can redeem it via plugin/API/get.json.php?APIName=login_code, which returns the target account’s email and a User::getUserHash(users_id, '+1 year') value; this hash is accepted as a credential in place of the account password for one year, enabling complete takeover of the victim’s account.

Affected Systems

All releases of the WWBN:AVideo platform that include the vulnerable getRandomCode() implementation, including the code base at commit c3edcc274c389816d434acadac07ee78eaf330c1 and earlier versions. No patched version is available.

Risk and Exploitability

With a CVSS score of 9.1, the vulnerability carries critical severity; the EPSS score is unavailable, and it is not listed in the CISA KEV catalog. The attack vector is unauthenticated remote, leveraging the exposed API endpoint and the ability to brute‑force the limited‑space activation code, with the oracle providing precise microtime to narrow the search; given the relatively small code space and the 10‑minute validity window, a skilled adversary can feasibly locate a valid code, making exploitation likely against any impacted installation.

Generated by OpenCVE AI on September 18, 2026 at 07:16 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Disable or restrictunauthenticated access to plugin/API/set.json.php and plugin/API/get.json.php endpoints using a firewall or server configuration
  • Introduce a rate‑limit and reduce the code validity window to a few seconds, then require authentication for code retrieval
  • Upgrade to a newer release of AVideo that employs a cryptographically secure random number generator and removes the vulnerable activation code mechanism

Generated by OpenCVE AI on September 18, 2026 at 07:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Description AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 uses a cryptographically weak pseudo-random number generator when creating account activation / login pairing codes. getRandomCode() in objects/functions.php derives the code entirely from uniqid() (sprintf('%08x%05x', seconds, microseconds)) with a single non-CSPRNG rand() character used only as padding, reducing the code space to roughly 36 x 10^6 (~2^25) values for a known generation second. Because plugin/API/set.json.php?APIName=login_code can be called without authentication, it also serves as an oracle for the server's exact microtime. An unauthenticated remote attacker who guesses a valid, unexpired code (codes expire after 10 minutes) can redeem it at plugin/API/get.json.php?APIName=login_code to obtain the target account's email address and a User::getUserHash(users_id, '+1 year') value, a credential accepted in place of the account password for one year, resulting in account takeover. No patched version is available.
Title AVideo Weak PRNG Activation Code Authentication Bypass
First Time appeared Wwbn
Wwbn avideo
Weaknesses CWE-330
CPEs cpe:2.3:a:wwbn:avideo:-:*:*:*:*:*:*:*
Vendors & Products Wwbn
Wwbn avideo
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 9.1, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-17T12:04:23.607Z

Reserved: 2026-09-17T11:07:29.772Z

Link: CVE-2026-92913

cve-icon Vulnrichment

Updated: 2026-09-17T12:04:19.683Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T12:18:30.290

Modified: 2026-09-22T20:43:58.793

Link: CVE-2026-92913

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T07:30:05Z

Weaknesses
  • CWE-330

    Use of Insufficiently Random Values