Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 16 Sep 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | AVideo through 29.0 contains a race condition in the enforceRateLimit() function that fails to atomically increment rate limit counters, allowing attackers to bypass all rate limits including login brute-force protection by issuing concurrent requests. Attackers can submit parallel credential attempts to exceed the documented 30-attempts-per-5-minutes login limit by an arbitrary factor determined only by their connection concurrency. | |
| Title | AVideo through 29.0 Rate Limit Bypass via Non-Atomic Counter Increment | |
| First Time appeared |
Wwbn
Wwbn avideo |
|
| Weaknesses | CWE-307 | |
| CPEs | cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Wwbn
Wwbn avideo |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-16T21:46:50.833Z
Reserved: 2026-09-16T13:47:20.117Z
Link: CVE-2026-92583
No data.
Status : Received
Published: 2026-09-16T22:18:28.747
Modified: 2026-09-16T22:18:28.747
Link: CVE-2026-92583
No data.
OpenCVE Enrichment
No data.
-
CWE-307
Improper Restriction of Excessive Authentication Attempts