Critical Zero-Click Command Injection in AVideo Platform Allows Stream Hijacking
ID: e3874be5-24a3-56c3-9735-24b398c1282b
STIX ID: report--e3874be5-24a3-56c3-9735-24b398c1282b
Feed Name: cybersecurityNews.com
**Executive Summary:** A critical zero-click command-injection vulnerability (CVE-2026-29058) in AVideo v6.0 allows unauthenticated attackers to execute arbitrary OS commands via a base64Url parameter in objects/getImage.php, potentially enabling full server compromise, credential exfiltration, and live-stream hijacking; AVideo 7.0+ contains the patch, and administrators should upgrade or apply mitigations such as IP allowlisting, WAF rules, or disabling the image retrieval endpoint.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
