
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33488 is a PGP 2FA bypass vulnerability in the WWBN AVideo LoginControl plugin caused by cryptographically broken 512-bit RSA key generation. The createKeys() function in plugin/LoginControl/pgp/functions.php generates 512-bit RSA keypairs — a key size publicly factorable since 1999 — allowing attackers who obtain a user's public key to factor the modulus, reconstruct the private key, and decrypt any 2FA challenge. Additionally, the generateKeys.json.php and encryptMessage.json.php endpoints lack authentication, enabling unauthenticated denial-of-service via CPU-intensive key generation. All WWBN AVideo versions up to and including 26.0 are affected. The vulnerability was published on March 20, 2026, with a CVSS v3.1 score of 8.1 (High) per Feedly data, or 7.4 (High) per the GitHub Advisory (GitHub Advisory, AVideo Advisory).
The root cause is CWE-326 (Inadequate Encryption Strength): the createKeys() function in plugin/LoginControl/pgp/functions.php (line 26) calls RSA::createKey(512), code copied verbatim from the singpolyma/openpgp-php library's demo code never intended for production use. During login, AVideo generates a uniqid() challenge token, encrypts it with the user's stored 512-bit public key, and requires the user to decrypt and submit the plaintext to verifyChallenge.json.php for verification. Because 512-bit RSA moduli can be factored in hours on commodity hardware using freely available tools (CADO-NFS, msieve, yafu), an attacker who retrieves the target's public key can reconstruct the private key and decrypt any challenge, fully bypassing 2FA. Compounding this, generateKeys.json.php and encryptMessage.json.php perform no authentication checks, exposing CPU-intensive operations to anonymous callers with no rate limiting (GitHub Advisory, AVideo Advisory).
Successful exploitation enables complete 2FA bypass for any account that used the built-in PGP key generator, rendering the second authentication factor entirely ineffective. Combined with credential compromise (via phishing, credential stuffing, or breach reuse), this allows full account takeover of 2FA-protected AVideo accounts, impacting confidentiality and integrity. Separately, the unauthenticated generateKeys.json.php endpoint allows any anonymous user to repeatedly trigger CPU-intensive RSA key generation, degrading server performance and potentially causing denial of service for all deployments with the LoginControl plugin (GitHub Advisory).
A proof-of-concept exploit with detailed step-by-step instructions is publicly available in the GitHub Security Advisory, including specific curl commands and Python code targeting real endpoints such as verifyChallenge.json.php (AVideo Advisory). Feedly classifies the exploit confidence as high, noting it provides sequential exploitation instructions covering RSA modulus extraction, factoring, private key reconstruction, and 2FA challenge submission. There is no current evidence of in-the-wild exploitation, no known threat actor attribution, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is approximately 0.029–0.044%, placing it in a low percentile for near-term exploitation probability (GitHub Advisory).
https://target/plugin/LoginControl/pgp/generateKeys.json.php?keyPassword=test&keyName=test&keyEmail=test@test.com — a successful JSON response with PGP key blocks confirms vulnerability.savePublicKey.json.php endpoint or any exposed user profile data).N using GPG or Python (from Crypto.PublicKey import RSA; print(key.n)).cado-nfs.py <N>) or msieve (msieve -v <N>) to factor N into primes p and q. This typically completes in 2–8 hours on a modern desktop.pycryptodome library, compute d = inverse(e, (p-1)*(q-1)) with e=65537 and reconstruct the RSA private key via RSA.construct((n, e, d, p, q)).verifyChallenge.json.php with the target's session cookie: curl -b "session_cookie" "https://target/plugin/LoginControl/pgp/verifyChallenge.json.php" -d "response=<plaintext>". A response of {"error":false} confirms successful 2FA bypass and account access (AVideo Advisory)./plugin/LoginControl/pgp/generateKeys.json.php with parameters keyPassword, keyName, keyEmail from unknown or repeated source IPs; unauthenticated requests to /plugin/LoginControl/pgp/encryptMessage.json.php./plugin/LoginControl/pgp/verifyChallenge.json.php from IPs not associated with the legitimate account holder, particularly following a successful password authentication.200 OK responses to generateKeys.json.php or encryptMessage.json.php without an authenticated session cookie.verifyChallenge.json.php) succeeding for accounts from unexpected geographic locations or IP addresses, especially shortly after credential-based login.generateKeys.json.php, indicative of a DoS attempt (AVideo Advisory).The fix is available in commit 00d979d87f8182095c8150609153a43f834e351e in the WWBN/AVideo repository; users should update to any version newer than 26.0 that includes this patch (AVideo Patch). The patch increases RSA key size from 512 to 2048 bits in functions.php, and adds authentication guards to both generateKeys.json.php and encryptMessage.json.php. Users who previously enabled PGP 2FA using the built-in key generator should disable and re-enroll 2FA after upgrading to regenerate keys at the secure size. As an interim workaround, restrict access to the generateKeys.json.php and encryptMessage.json.php endpoints via WAF rules or web server configuration, and add minimum key size validation (2048-bit minimum) in savePublicKey.json.php to reject previously generated weak keys (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."