CVE-2026-100299

Summary

In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, the device includes a legacy password hash on the serial console that relies on a weak DES‑based encryption.

Affected Software

VendorProductVersion RangeStatus
AnjvisionYSSD-RTMP-H5Version 3.3.2.4 build 2024-12-26affected

Weaknesses

  • CWE-1391: CWE-1391 Use of Weak Credentials

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References