Cryptographically Weak RTMP Publish Keys in AVideo by WWBN
CVE-2026-92912
8.3HIGH
What is CVE-2026-92912?
AVideo utilizes a weak method for generating RTMP publish keys through the cryptographically insecure uniqid() function. This approach drastically reduces the entropy to approximately one million possibilities per second. If an attacker is aware of the channel creation time, they can effectively brute-force the five-digit microsecond component to produce valid stream keys, enabling them to impersonate the channel owner and broadcast unauthorized content.
Affected Version(s)
AVideo 0
