CVE-2026-100291
In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, several ONVIF service endpoints process management requests without enforcing required authentication. This could allow an unauthorized attacker to access sensitive device operations.
CVSS score9.8 / 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HWeakness type (CWE)CWE-1188
Related articles
This product uses the NVD API but is not endorsed or certified by the NVD.
