OS Command Injection in WWBN AVideo Open Source Video Platform
CVE-2026-55173
What is CVE-2026-55173?
The OS command injection vulnerability in the WWBN AVideo platform allows attackers to execute arbitrary commands on the server. Despite a prior fix for a related vulnerability, the latest versions still permit exploitation through incomplete input sanitization. The vulnerability arises when an attacker crafts a malicious encrypted payload that is then executed via the 'execAsync' function. This flaw remains due to a failure to mitigate specific shell operators, enabling potential command chains and unauthorized access to the system. The issue can be traced back to the command construction method utilized in the system, which inadequately handles certain command syntax. A patch has been released to address this vulnerability, reinforcing the importance of maintaining updated software versions.
Affected Version(s)
AVideo <= 29.0
