Summary
CVE-2026-64625 is a critical OS Command Injection vulnerability (CWE-78) in WWBN AVideo, affecting all versions before 29.0. The flaw is an incomplete fix for CVE-2026-45578: the execAsync() helper function in objects/functionsExec.php applies only addcslashes() to escape double-quote characters but does not neutralize $() command substitution syntax or backticks, leaving them active within the double-quoted sh -c "$command" shell context it constructs. An unauthenticated remote attacker can exploit this via the Live plugin’s on_publish.php endpoint to execute arbitrary OS commands on the server. The vulnerability is rated CVSS 4.0: 9.3 Critical.
Technical details
- Root cause:
execAsync()inobjects/functionsExec.phpassembles shell commands and wraps them insh -c "$command"using double-quoted syntax. The function appliesaddcslashes($command, '"'), which escapes double-quote characters but leaves dollar signs and backticks unescaped. Although individual tokens may be processed withescapeshellarg()— the fix introduced for CVE-2026-45578 — the reassembled command string is placed back inside a double-quoted shell context where$()and backtick command substitution remain active and are interpreted by the shell. - Trigger conditions: An attacker sends a crafted HTTP request to the unauthenticated
plugin/Live/on_publish.phpendpoint, injecting a payload containing$()or backtick syntax via a controllable parameter (such as the stream key used to construct the M3U8 file path). - Attack vector: Network-accessible; no authentication required, no user interaction required.
- Impact: Arbitrary OS command execution on the underlying server, resulting in full compromise of confidentiality, integrity, and availability.
Affected software
- WWBN AVideo: all versions before 29.0
Severity
- CVSS v3.1 Base Score: 9.8 Critical
- Vector string:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Upgrade WWBN AVideo to version 29.0 or later.
- If immediate upgrade is not feasible: Restrict access to the
plugin/Live/on_publish.phpendpoint at the web server or network perimeter level (e.g., via.htaccessor nginx rules), limiting access exclusively to localhost and authorized RTMP server IP addresses.
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

