Nine Flaws Leave Anjvision Video Devices Exposed Without a Planned Firmware Fix

CISA disclosed nine flaws in Anjvision YSSD-RTMP-H5 firmware, including unauthenticated access and RCE, with CVSS 9.8 and no fix planned.

Nine Flaws Leave Anjvision Video Devices Exposed Without a Planned Firmware Fix
Vulnerabilities

Illustrative image generated with AI

Listen to this articleAudio edition · 10 min

CISA has disclosed nine vulnerabilities in the Anjvision YSSD-RTMP-H5, an industrial video device deployed worldwide in commercial facilities. The flaws range from information disclosure and server-side request forgery to unauthenticated management access and potential operating-system command execution.

The ICS advisory published on September 29, 2026 assigns the group a headline CVSS v3 score of 9.8. Anjvision has not provided a remediation plan, according to CISA, and did not respond to requests to coordinate mitigation.

All nine vulnerabilities affect YSSD-RTMP-H5 firmware 3.3.2.4_build_2024-12-26. Devices running other releases are not identified as vulnerable in the available information.

Unauthenticated access creates the most direct route to compromise

The most severe issue, CVE-2026-100291, affects several ONVIF service endpoints. Those interfaces process management requests without consistently requiring authentication, allowing a remote attacker to reach sensitive device operations without credentials or user interaction.

The vulnerability carries a CVSS v3.1 score of 9.8 and a CVSS v4.0 score of 9.3. Its v3.1 vector—CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H—indicates network-based exploitation, low attack complexity, no required privileges, and potential high impact across confidentiality, integrity, and availability.

The CVE Program classifies the condition as CWE-1188, initialization of a resource with an insecure default. Its CVE Program record independently identifies firmware version 3.3.2.4 build 2024-12-26 as affected and lists the product’s default status as unaffected.

A second unauthenticated weakness, CVE-2026-100297, exposes a network-check function that can be directed toward arbitrary hosts. This creates a server-side request forgery capability from the device’s position inside a network.

An attacker could use that behavior to probe internal systems that are not otherwise reachable or cause information to leave through DNS requests. The issue is rated 5.3 under CVSS v3.1 and 6.9 under CVSS v4.0.

Debug functions and update handling could enable deeper control

Several of the vulnerabilities provide paths from application access to more powerful device functionality.

CVE-2026-100292 allows an authenticated attacker to enable a hidden debug interface. Requests sent through that interface can reach a backend command service, creating an OS command-injection risk when crafted input reaches the underlying handler. It is rated 8.8 under CVSS v3.1 and 8.7 under CVSS v4.0.

A related issue, CVE-2026-100295, concerns an undocumented mechanism for activating an internal debug interface. Once enabled, it exposes functions that are not intended for standard device operation and may permit elevated system access. CISA assigns it a CVSS v3.1 score of 6.3, rising to 7.1 under CVSS v4.0.

Firmware integrity is also affected. CVE-2026-100293 exists because the local and cloud update processes do not verify firmware with a cryptographic signature. Instead, they rely on basic hashing, which does not establish that an image came from a trusted publisher.

An attacker capable of reaching the update routine could therefore submit an untrusted firmware image that the device accepts as valid. The vulnerability scores 8.8 under CVSS v3.1 and 8.7 under CVSS v4.0.

Together, the debug and update flaws could provide durable control beyond a single unauthorized request. The available information does not describe a demonstrated exploit chain connecting them.

Shared secrets and account-handling defects expose credentials

The firmware contains cloud API credentials shared across deployed devices. Tracked as CVE-2026-100294, the weakness allows anyone who obtains the publicly available firmware package to recover and potentially reuse those values against the associated cloud service.

Because no prior authentication is required to extract credentials from the firmware, the issue has a CVSS v3.1 score of 7.5. Its CVSS v4.0 rating is 8.7.

CVE-2026-100298 affects two user-information endpoints that can reveal sensitive device and account details under unintended conditions. CISA classifies it as insufficient protection of credentials and gives it scores of 8.8 under CVSS v3.1 and 8.7 under CVSS v4.0.

Another account-management flaw has an unusual trigger. An authenticated user can send an empty-body POST request to /setUserConfig, which the web server dispatches through its SOAP-RPC handler. The request resets the administrator password to its default and damages the in-memory authentication state until the device reloads.

That vulnerability, CVE-2026-100296, occurs because the handler fails to validate the requester’s session privilege level and mishandles the exceptional empty-body condition. It scores 8.1 under CVSS v3.1 and 7.2 under CVSS v4.0.

The final issue, CVE-2026-100299, is local rather than network-based. The serial console contains a legacy password hash protected with weak DES-based encryption. Physical access is required under the supplied CVSS v3.1 vector, but successful exploitation could affect confidentiality, integrity, and availability. It is rated 6.8 under CVSS v3.1 and 7.0 under CVSS v4.0.

Worldwide deployments face confidentiality and control risks

CISA places the affected product in the Commercial Facilities sector and says it is deployed worldwide. Anjvision is headquartered in China.

The practical consequences depend on which interface an attacker can reach and whether credentials are already available. Possible outcomes include disclosure of account information, internal-network reconnaissance, password resets, unauthorized firmware installation, command execution, and full device control.

Internet-exposed systems face the clearest immediate risk because several flaws are remotely reachable and two require no authentication. Low-privileged users can also trigger multiple high-impact conditions, including the debug-command pathway and administrator-password reset.

Andrew Lee reported the vulnerabilities to CISA. It is not known whether attackers have exploited any of them in operational environments, and no device-specific indicators of compromise have been published.

The available information does not identify any of these vulnerabilities as entries in CISA’s Known Exploited Vulnerabilities catalog. Consequently, no KEV remediation deadline or ransomware-use flag has been reported.

No patch is planned, making exposure reduction the primary defense

CISA reports that no fix is planned. There is no firmware update or vulnerability-specific workaround available, and Anjvision did not engage with CISA on mitigation. Customers are directed to contact Anjvision support for further information.

Until a supported correction becomes available, organizations should identify every YSSD-RTMP-H5 device and verify its firmware. Systems running 3.3.2.4_build_2024-12-26 should be treated as vulnerable.

Operators should then apply compensating controls:

  • Remove direct internet access to the device and its management interfaces.
  • Place video and control-system equipment behind firewalls.
  • Separate affected devices from business networks and sensitive internal services.
  • Restrict ONVIF, web management, SOAP-RPC, update, and cloud-related traffic to necessary systems.
  • Allow remote administration only through maintained, appropriately secured VPN infrastructure.
  • Review device accounts, administrator-password changes, firmware-update activity, and unexpected debug-interface behavior.
  • Monitor DNS and outbound connections for unexplained requests originating from affected devices.

No product-specific compromise indicators are available, so monitoring must focus on behavioral anomalies and unauthorized configuration changes. Organizations should conduct an impact and risk assessment before applying network restrictions, particularly where the devices support safety, surveillance, or operational processes.

Read next

Sources

This article is an original reworking based on the sources below.

CVEs covered in this article

Back to home

Latest Cybersecurity News

All cybersecurity news →