#VU125465 Inadequate Encryption Strength in AVideo - CVE-2026-33488
Published: April 8, 2026
AVideo
World Wide Broadcast Network
Description
The vulnerability allows a remote attacker to bypass two-factor authentication and take over an account.
The vulnerability exists due to inadequate encryption strength in the LoginControl plugin PGP 2FA key generation function when generating RSA keys for PGP-based login challenges. A remote attacker can obtain a target user's public key, factor the 512-bit RSA modulus, and decrypt the challenge to bypass two-factor authentication and take over an account.
Only accounts that enabled PGP 2FA using the built-in key generator are affected; users who imported adequately sized external keys are not affected by the weak-key issue.