CVE-2025-34441 is a high-severity information disclosure vulnerability affecting AVideo versions prior to 20.1. It allows unauthenticated attackers to access sensitive user data, including emails and administrative status, via a public API endpoint. With a CVSS score of 7.5 (HIGH) and an EPSS score indicating high exploitability, this flaw enables user enumeration and privacy violations. While not yet in CISA's KEV catalog, a Metasploit module exists, and the vulnerability has garnered significant community discussion, suggesting potential for active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 20.0CPE matchmatch criteria | cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.