Impact
AVideo's activation code generation relies on a cryptographically weak pseudo‑random number generator, deriving the code from the server’s timestamp and a single non‑cryptographic random character, resulting in an effective code space of roughly 36×10⁶ (about 2²⁵) distinct values for a known second. The endpoint plugin/API/set.json.php?APIName=login_code is callable without authentication, serving as an oracle that reveals the exact server microtime. An unauthenticated remote attacker who guesses a valid, unexpired code within the ten‑minute validity window can redeem it via plugin/API/get.json.php?APIName=login_code, which returns the target account’s email and a User::getUserHash(users_id, '+1 year') value; this hash is accepted as a credential in place of the account password for one year, enabling complete takeover of the victim’s account.
Affected Systems
All releases of the WWBN:AVideo platform that include the vulnerable getRandomCode() implementation, including the code base at commit c3edcc274c389816d434acadac07ee78eaf330c1 and earlier versions. No patched version is available.
Risk and Exploitability
With a CVSS score of 9.1, the vulnerability carries critical severity; the EPSS score is unavailable, and it is not listed in the CISA KEV catalog. The attack vector is unauthenticated remote, leveraging the exposed API endpoint and the ability to brute‑force the limited‑space activation code, with the oracle providing precise microtime to narrow the search; given the relatively small code space and the 10‑minute validity window, a skilled adversary can feasibly locate a valid code, making exploitation likely against any impacted installation.
OpenCVE Enrichment