CVE-2026-100291
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Summary
In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, several ONVIF service endpoints process management requests without enforcing required authentication. This could allow an unauthorized attacker to access sensitive device operations.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Anjvision | YSSD-RTMP-H5 | Version 3.3.2.4 build 2024-12-26 | affected |
Weaknesses
- CWE-1188: CWE-1188 Initialization of a resource with an insecure default
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: yes
- Technical Impact: total
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.