8.8
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Description
A race condition vulnerability exists in the aVideoEncoder.json.php unzip functionality of WWBN AVideo 14.4 and dev master commit 8a8954ff. A series of specially crafted HTTP request can lead to arbitrary code execution.
Basic Information
ID
CVE-2025-25214
Source
talos
Published
Jul 24, 2025 at 15:10
Modified
Jul 24, 2025 at 15:32
Affected Product
Vendor
WWBN
Product
AVideo
Version
14.4
Affected Versions
WWBN AVideo 14.4
WWBN AVideo dev master commit 8a8954ff
WWBN AVideo dev master commit 8a8954ff