#VU125449 Missing Authentication for Critical Function in AVideo
Published: April 8, 2026
AVideo
World Wide Broadcast Network
Description
The vulnerability allows a remote attacker to disclose sensitive information and cause a denial of service.
The vulnerability exists due to missing authentication for a critical function in decryptMessage.json.php when handling decryption requests. A remote attacker can send specially crafted decryption requests to disclose sensitive information and cause a denial of service.
Submitted private key material may be exposed through server memory or logging infrastructure depending on server configuration.