CVE-2025-25214
8.8WWBN · AVideo
A race condition in the aVideoEncoder.json.php unzip functionality of WWBN AVideo allows authenticated attackers to achieve arbitrary code execution via crafted HTTP requests.
Executive summary
A critical race condition in WWBN AVideo allows authenticated attackers to execute arbitrary code on the host system, posing a severe risk to server integrity.
Vulnerability
This vulnerability is a race condition (CWE-362) within the unzip functionality of the aVideoEncoder.json.php file. An authenticated attacker can trigger this flaw by sending a series of specially crafted HTTP requests to achieve arbitrary code execution.
Business impact
Successful exploitation of this vulnerability grants an attacker the ability to execute arbitrary code on the underlying server. Given the CVSS score of 8.8, this represents a high-severity risk that could lead to full system compromise, data exfiltration, and unauthorized access to sensitive video content and administrative configurations.
Remediation
Immediate Action: Since a specific patch is not currently identified, users should restrict access to the aVideoEncoder.json.php endpoint and monitor vendor channels for an official security update.
Proactive Monitoring: Security teams should review server access logs for anomalous, high-frequency HTTP requests targeting the aVideoEncoder.json.php endpoint.
Compensating Controls: Deploy a Web Application Firewall (WAF) rule to inspect and block suspicious or malformed HTTP requests directed at the AVideo encoder functionality.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
The potential for arbitrary code execution necessitates immediate attention from administrators. We recommend isolating the affected AVideo instance from untrusted network segments and monitoring for any suspicious activity until an official vendor patch is released and applied.
More WWBN CVEs
Sources
Originally found and disclosed by Discovered by Claudio Bozzato of Cisco Talos., per the CVE Program record.