Cryptographically Weak RTMP Publish Keys in AVideo by WWBN
CVE-2026-92912

8.3HIGH

Key Information:

Vendor

Wwbn

Status
Vendor
CVE Published:
17 September 2026

What is CVE-2026-92912?

AVideo utilizes a weak method for generating RTMP publish keys through the cryptographically insecure uniqid() function. This approach drastically reduces the entropy to approximately one million possibilities per second. If an attacker is aware of the channel creation time, they can effectively brute-force the five-digit microsecond component to produce valid stream keys, enabling them to impersonate the channel owner and broadcast unauthorized content.

Affected Version(s)

AVideo 0

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

santhreal
.