PT-2026-102824 · Anjvision · Yssd-Rtmp-H5

·

CVE-2026-100291

·

Published

2026-09-29

·

Updated

2026-09-30

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Anjvision YSSD-RTMP-H5 version 3.3.2.4
Description Several ONVIF service endpoints process management requests without enforcing required authentication. This issue stems from the initialization of a resource with an insecure default, which could allow an unauthorized attacker to access sensitive device operations. This flaw can be chained with other vulnerabilities to achieve complete device compromise, including privilege escalation, lateral movement through Server-Side Request Forgery (SSRF), and firmware manipulation.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100291

Affected Products

Yssd-Rtmp-H5