Streaming Nightmare: Unpatched CVSS 10.0 Flaws Leave AVideo Servers Wide Open
ID: cd20532e-4919-5fab-9c2a-da9cf491ae45
STIX ID: report--cd20532e-4919-5fab-9c2a-da9cf491ae45
Feed Name: securityonline.info
## Executive Summary The report details five critical, unpatched vulnerabilities in the AVideo streaming platform (all deployments up to v26.0) — including a multi-stage RCE chain (CVE-2026-33478), SQL injection (CVE-2026-33352), live-stream control takeover (CVE-2026-33716), DVR token bypass/SSRF (CVE-2026-33351), and SSRF via a leftover test script (CVE-2026-33502) — that together allow unauthenticated attackers to dump databases (including emails and MD5 password hashes), gain admin access, execute arbitrary commands, deploy web shells, hijack or record live streams, and pivot into internal networks; the report urges immediate manual mitigations (remove plugin/Live/test.php, restrict CloneSite plugin, upgrade password hashing, apply parameterized queries and command escaping) since no patched versions are available.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
