Race Condition in WWBN AVideo 14.4 Unzip Functionality
CVE-2025-25214

8.8HIGH

Key Information:

Vendor

Wwbn

Status
Vendor
CVE Published:
24 July 2025

What is CVE-2025-25214?

A race condition vulnerability in the unzip functionality of aVideoEncoder.json.php in WWBN AVideo allows attackers to exploit a flaw through a series of crafted HTTP requests. This security weakness could lead to potential arbitrary code execution, offering malicious actors an entry point to compromise the system.

Affected Version(s)

AVideo 14.4

AVideo dev master commit 8a8954ff

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Discovered by Claudio Bozzato of Cisco Talos.
.