CVE-2025-25214

8.8

WWBN · AVideo

A race condition in the aVideoEncoder.json.php unzip functionality of WWBN AVideo allows authenticated attackers to achieve arbitrary code execution via crafted HTTP requests.

Executive summary

A critical race condition in WWBN AVideo allows authenticated attackers to execute arbitrary code on the host system, posing a severe risk to server integrity.

Vulnerability

This vulnerability is a race condition (CWE-362) within the unzip functionality of the aVideoEncoder.json.php file. An authenticated attacker can trigger this flaw by sending a series of specially crafted HTTP requests to achieve arbitrary code execution.

Business impact

Successful exploitation of this vulnerability grants an attacker the ability to execute arbitrary code on the underlying server. Given the CVSS score of 8.8, this represents a high-severity risk that could lead to full system compromise, data exfiltration, and unauthorized access to sensitive video content and administrative configurations.

Remediation

Immediate Action: Since a specific patch is not currently identified, users should restrict access to the aVideoEncoder.json.php endpoint and monitor vendor channels for an official security update.

Proactive Monitoring: Security teams should review server access logs for anomalous, high-frequency HTTP requests targeting the aVideoEncoder.json.php endpoint.

Compensating Controls: Deploy a Web Application Firewall (WAF) rule to inspect and block suspicious or malformed HTTP requests directed at the AVideo encoder functionality.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

The potential for arbitrary code execution necessitates immediate attention from administrators. We recommend isolating the affected AVideo instance from untrusted network segments and monitoring for any suspicious activity until an official vendor patch is released and applied.

More WWBN CVEs

Sources

Originally found and disclosed by Discovered by Claudio Bozzato of Cisco Talos., per the CVE Program record.