Executive brief
WWBN AVideo is an open-source video hosting and streaming platform. The vulnerability allows unauthenticated attackers to forge authentication tokens using publicly available information (the site's base URL and current time), gaining unauthorized access to a password hashing endpoint. An attacker can then submit arbitrary passwords to obtain encrypted hashes, enabling offline precomputation attacks against stolen password databases and compromising user accounts.
Technical details
This is a cryptographic authentication bypass in encryptPass.json.php where the HMAC gate was meant to verify authorized callers but instead uses a public value (the site's base URL) as the secret key instead of an actual shared secret. The vulnerability stems from CWE-321 (hard-coded cryptographic key) and CWE-807 (reliance on untrusted inputs in security decisions). The HMAC message is floor(time() / 300), a publicly derivable clock value, and the implementation accepts a five-window time range, eliminating the need for accurate clock synchronization. An attacker can compute a valid token with one hash_hmac call from knowledge of the site URL and current time, both publicly available. The endpoint then acts as an unauthenticated password hashing oracle, allowing an attacker to precompute encrypted password hashes against stolen or dictionary-sourced passwords. Network-accessible, no authentication required, low complexity attack requiring only the ability to visit the site.
Affected products
- WWBN AVideo through commit 9c39d8c8
Timeline
- 2026-09-01: disclosed