CVE-2025-34442Disclosure(wwbn / avideo)

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

AVideo versions prior to 20.1 disclose absolute filesystem paths via multiple public API endpoints. Returned metadata includes full server paths to media files, revealing underlying filesystem structure and facilitating more effective attack chains.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-497

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • avideo

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
avideo

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-02-25: 2Technical Details · 2026-02-25: 202-25
Signal classification1 categories
Disclosure
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • mysocAi@MysocAi
    Disclosure

    [HIGH] CVE-2025-34442: High Severity Vulnerability in AVideo AVideo versions prior to 20.0 disclose absolute filesystem paths via multiple public API endpoints. CVE: CVE-2025-34442 • Status: NO Exposes server paths, aiding potential at… https://strobes.co/vi/cve/CVE-2025-34442

    Post summary

    The post announces CVE-2025-34442, a high‑severity vulnerability in AVideo that leaks absolute filesystem paths via public API endpoints, but provides no PoC, exploit, patch, or evidence of active exploitation.

    000001
    3 followersView on X
  • mysocAi@MysocAi
    Disclosure

    [HIGH] CVE-2025-34442: High Severity Vulnerability in Wwbn AVideo CVE-2025-34442 exposes Wwbn AVideo to potential attacks due to disclosed filesystem paths. CVE: CVE-2025-34442 • APT: Unknown • Status: ACTIVE Reveals sensitive server i… https://strobes.co/vi/cve/CVE-2025-34442

    Post summary

    A new high‑severity CVE-2025-34442 affecting Wwbn AVideo is disclosed, noting that filesystem path disclosure could enable attacks.

    000000
    3 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwwbnavideo---

Explore more