CVE-2026-86187
published 2026-09-05CVE-2026-86187: WWBN AVideo generates passwords for external-login accounts using rand() instead of a cryptographic generator, producing only 31-bit integers. Attackers with…
PriorityP433medium5.9CVSS 3.1
AVNACHPRHUINSUCHIHAN
EPSS
0.36%
27.6th percentile
WWBN AVideo generates passwords for external-login accounts using rand() instead of a cryptographic generator, producing only 31-bit integers. Attackers with access to password hashes can recover plaintext passwords in minutes through offline brute-force attacks due to unsalted MD5-based hashing.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| wwbn | avideo | <= 29.0 | — |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N
nvdv4.07.4HIGHCVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
WWBN AVideo up to 29.0 rand random values
vuldb·2026-09-05·CVSS 5.9
CVE-2026-86187 [MEDIUM] WWBN AVideo up to 29.0 rand random values
A vulnerability labeled as problematic has been found in WWBN AVideo up to 29.0. Affected is the function rand. Such manipulation leads to insufficiently random values.
This vulnerability is uniquely identified as CVE-2026-86187. The attack can be launched remotely. No exploit exists.
GHSA
WWBN AVideo generates passwords for external-login accounts using rand() instead of a cryptographic generator, producing only 31-bit integers.
ghsa_unreviewed·2026-09-05
CVE-2026-86187 [HIGH] CWE-330 WWBN AVideo generates passwords for external-login accounts using rand() instead of a cryptographic generator, producing only 31-bit integers.
WWBN AVideo generates passwords for external-login accounts using rand() instead of a cryptographic generator, producing only 31-bit integers. Attackers with access to password hashes can recover plaintext passwords in minutes through offline brute-force attacks due to unsalted MD5-based hashing.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-09-05
Published