CVE-2025-48732: Critical severity WWBN AVideo vulnerability
An incomplete blacklist exists in the .htaccess sample of WWBN AVideo 14.4 and dev master commit 8a8954ff. A specially crafted HTTP request can lead to a arbitrary code execution. An attacker can request a .phar file to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48732?
CVE-2025-48732 is classified as a high severity vulnerability due to its potential for arbitrary code execution.
How do I fix CVE-2025-48732?
To fix CVE-2025-48732, ensure that your .htaccess file includes a complete and correct blacklist that prevents the execution of .phar files.
What is the exploitation method for CVE-2025-48732?
CVE-2025-48732 can be exploited by sending a specially crafted HTTP request that accesses a vulnerable .phar file.
Which software versions are affected by CVE-2025-48732?
CVE-2025-48732 affects WWBN AVideo version 14.4 and the dev master commit identified as 8a8954ff.
What impact does CVE-2025-48732 have on the system?
The impact of CVE-2025-48732 includes the potential for an attacker to execute arbitrary code on the server, compromising system security.