Impact
AVideo LoginControl contains a flaw in its PGP second factor verification where the challenge response is compared using loose equality against an uninitialized session variable. This leads to null == null being true, allowing an attacker who knows a victim’s password to complete authentication without supplying a second factor. The vulnerability enables an attacker to gain authenticated access to the system by simply requesting the verifyChallenge endpoint with no parameters, thereby bypassing the intended two‑factor protection.
Affected Systems
The weakness affects the AVideo content‑management platform developed by WWBN. No specific version information is provided in the advisory, so all installations of AVideo should be evaluated for the presence of the unauthenticated verifyChallenge.json.php handler.
Risk and Exploitability
The CVSS score of 8.6 classifies this defect as high severity. EPSS information is not available, but the attack requires only a valid password and a simple HTTP GET request, so it can be remotely exploited via the public web interface. The vulnerability is not currently listed in the CISA KEV catalog, indicating no known widespread exploitation, yet the high impact and remote nature warrant close attention.
OpenCVE Enrichment