WWBN AVideo generates passwords for external-login accounts using rand() instead of a cryptographic generator, producing only 31-bit integers. Attackers with access to password hashes can recover plaintext passwords in minutes through offline brute-force attacks due to unsalted MD5-based hashing.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 05 Sep 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | WWBN AVideo generates passwords for external-login accounts using rand() instead of a cryptographic generator, producing only 31-bit integers. Attackers with access to password hashes can recover plaintext passwords in minutes through offline brute-force attacks due to unsalted MD5-based hashing. | |
| Title | WWBN AVideo Weak PRNG Password Generation via External Login | |
| First Time appeared |
Wwbn
Wwbn avideo |
|
| Weaknesses | CWE-330 | |
| CPEs | cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Wwbn
Wwbn avideo |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-05T12:09:03.422Z
Reserved: 2026-09-05T11:51:31.101Z
Link: CVE-2026-86187
No data.
Status : Received
Published: 2026-09-05T13:18:13.703
Modified: 2026-09-05T13:18:13.703
Link: CVE-2026-86187
No data.
OpenCVE Enrichment
Updated: 2026-09-05T13:30:05Z
Weaknesses