PT-2026-102824 · Anjvision · Yssd-Rtmp-H5
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Anjvision YSSD-RTMP-H5 version 3.3.2.4
Description
Several ONVIF service endpoints process management requests without enforcing required authentication. This issue stems from the initialization of a resource with an insecure default, which could allow an unauthorized attacker to access sensitive device operations. This flaw can be chained with other vulnerabilities to achieve complete device compromise, including privilege escalation, lateral movement through Server-Side Request Forgery (SSRF), and firmware manipulation.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
LPE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Yssd-Rtmp-H5