Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-92912— AVideo Cryptographically Weak PRNG via uniqid Stream Key

Quick assessment

Affected
WWBN AVideo
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

AVideo(commit 标识 c3edcc274c389816d434acadac07ee78eaf330c1)中的 LiveTransmition 功能使用密码学上强度较弱的 生成 RTMP 推流密钥,导致密钥熵值降低,使得每个创建秒数内仅有约一百万种可能的组合。攻击者如果知晓频道的创建时间,即可通过暴力破解五位数的微秒部分,伪造出有效的推流密钥,从而以频道所有者的身份广播内容。

CVSS 6.5 · Medium

Possible ATT&CK Techniques 1 AI

T1557 · Adversary-in-the-Middle
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-92912

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
AVideo Cryptographically Weak PRNG via uniqid Stream Key
Source: CVE Program / CVE List V5
Vulnerability Description
AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 uses cryptographically weak uniqid() values for RTMP publish keys in LiveTransmition, reducing key entropy to approximately one million possibilities per creation second. Attackers who know the channel creation time can brute-force the five-digit microsecond component to forge valid stream keys and broadcast content as the channel owner.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
使用不充分的随机数
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
WWBN AVideo 0 ~ c3edcc274c389816d434acadac07ee78eaf330c1 -

II. Public POCs for CVE-2026-92912

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-92912

登录查看更多情报信息。

Vendor Advisories for CVE-2026-92912 (2)

Same Patch Batch · WWBN · 2026-09-17 · 4 CVEs total

CVE-2026-92914 8.1 HIGH AVideo LoginControl PGP Second Factor Authentication Bypass
CVE-2026-92913 7.4 HIGH AVideo Weak PRNG Activation Code Authentication Bypass
CVE-2026-92915 7.3 HIGH WWBN AVideo userVerifyEmail.php Unauthenticated Access Control

IV. Related Vulnerabilities

V. Comments for CVE-2026-92912

No comments yet


Leave a comment