{"id":"CVE-2025-34433","summary":"AVideo \u003c 20.1 Unauthenticated RCE via Predictable Installation Salt","details":"AVideo versions 14.3.1 prior to 20.1 contain an unauthenticated remote code execution vulnerability caused by predictable generation of an installation salt using PHP uniqid(). The installation timestamp is exposed via a public endpoint, and a derived hash identifier is accessible through unauthenticated API responses, allowing attackers to brute-force the remaining entropy. The recovered salt can then be used to encrypt a malicious payload supplied to a notification API endpoint that evaluates attacker-controlled input, resulting in arbitrary code execution as the web server user.","modified":"2026-08-12T03:51:32.206497782Z","published":"2025-12-19T15:37:39.775Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/34xxx/CVE-2025-34433.json","unresolved_ranges":[{"extracted_events":[{"introduced":"14.3.1"},{"fixed":"20.1"}],"source":"AFFECTED_FIELD"},{"extracted_events":[{"introduced":"14.3.1"},{"fixed":"20.1"}],"source":"CPE_FIELD"}],"cna_assigner":"VulnCheck","cwe_ids":["CWE-94"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/34xxx/CVE-2025-34433.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-34433"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/avideo-unauthenticated-rce-via-predictable-installation-salt"},{"type":"FIX","url":"https://github.com/WWBN/AVideo/commit/4a53ab2"},{"type":"FIX","url":"https://github.com/WWBN/AVideo/commit/a2bdbff"},{"type":"EVIDENCE","url":"https://chocapikk.com/posts/2025/avideo-security-vulnerabilities/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/wwbn/avideo","events":[{"introduced":"0"},{"fixed":"4a53ab2"},{"fixed":"a2bdbff"}],"database_specific":{"source":"REFERENCES"}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-34433.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}