Nine Flaws Leave Anjvision Video Devices Exposed Without a Planned Firmware Fix
CISA disclosed nine flaws in Anjvision YSSD-RTMP-H5 firmware, including unauthenticated access and RCE, with CVSS 9.8 and no fix planned.
Illustrative image generated with AI
CISA has disclosed nine vulnerabilities in the Anjvision YSSD-RTMP-H5, an industrial video device deployed worldwide in commercial facilities. The flaws range from information disclosure and server-side request forgery to unauthenticated management access and potential operating-system command execution.
The ICS advisory published on September 29, 2026 assigns the group a headline CVSS v3 score of 9.8. Anjvision has not provided a remediation plan, according to CISA, and did not respond to requests to coordinate mitigation.
All nine vulnerabilities affect YSSD-RTMP-H5 firmware 3.3.2.4_build_2024-12-26. Devices running other releases are not identified as vulnerable in the available information.
Unauthenticated access creates the most direct route to compromise
The most severe issue, CVE-2026-100291, affects several ONVIF service endpoints. Those interfaces process management requests without consistently requiring authentication, allowing a remote attacker to reach sensitive device operations without credentials or user interaction.
The vulnerability carries a CVSS v3.1 score of 9.8 and a CVSS v4.0 score of 9.3. Its v3.1 vector—CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H—indicates network-based exploitation, low attack complexity, no required privileges, and potential high impact across confidentiality, integrity, and availability.
The CVE Program classifies the condition as CWE-1188, initialization of a resource with an insecure default. Its CVE Program record independently identifies firmware version 3.3.2.4 build 2024-12-26 as affected and lists the product’s default status as unaffected.
A second unauthenticated weakness, CVE-2026-100297, exposes a network-check function that can be directed toward arbitrary hosts. This creates a server-side request forgery capability from the device’s position inside a network.
An attacker could use that behavior to probe internal systems that are not otherwise reachable or cause information to leave through DNS requests. The issue is rated 5.3 under CVSS v3.1 and 6.9 under CVSS v4.0.
Debug functions and update handling could enable deeper control
Several of the vulnerabilities provide paths from application access to more powerful device functionality.
CVE-2026-100292 allows an authenticated attacker to enable a hidden debug interface. Requests sent through that interface can reach a backend command service, creating an OS command-injection risk when crafted input reaches the underlying handler. It is rated 8.8 under CVSS v3.1 and 8.7 under CVSS v4.0.
A related issue, CVE-2026-100295, concerns an undocumented mechanism for activating an internal debug interface. Once enabled, it exposes functions that are not intended for standard device operation and may permit elevated system access. CISA assigns it a CVSS v3.1 score of 6.3, rising to 7.1 under CVSS v4.0.
Firmware integrity is also affected. CVE-2026-100293 exists because the local and cloud update processes do not verify firmware with a cryptographic signature. Instead, they rely on basic hashing, which does not establish that an image came from a trusted publisher.
An attacker capable of reaching the update routine could therefore submit an untrusted firmware image that the device accepts as valid. The vulnerability scores 8.8 under CVSS v3.1 and 8.7 under CVSS v4.0.
Together, the debug and update flaws could provide durable control beyond a single unauthorized request. The available information does not describe a demonstrated exploit chain connecting them.
Shared secrets and account-handling defects expose credentials
The firmware contains cloud API credentials shared across deployed devices. Tracked as CVE-2026-100294, the weakness allows anyone who obtains the publicly available firmware package to recover and potentially reuse those values against the associated cloud service.
Because no prior authentication is required to extract credentials from the firmware, the issue has a CVSS v3.1 score of 7.5. Its CVSS v4.0 rating is 8.7.
CVE-2026-100298 affects two user-information endpoints that can reveal sensitive device and account details under unintended conditions. CISA classifies it as insufficient protection of credentials and gives it scores of 8.8 under CVSS v3.1 and 8.7 under CVSS v4.0.
Another account-management flaw has an unusual trigger. An authenticated user can send an empty-body POST request to /setUserConfig, which the web server dispatches through its SOAP-RPC handler. The request resets the administrator password to its default and damages the in-memory authentication state until the device reloads.
That vulnerability, CVE-2026-100296, occurs because the handler fails to validate the requester’s session privilege level and mishandles the exceptional empty-body condition. It scores 8.1 under CVSS v3.1 and 7.2 under CVSS v4.0.
The final issue, CVE-2026-100299, is local rather than network-based. The serial console contains a legacy password hash protected with weak DES-based encryption. Physical access is required under the supplied CVSS v3.1 vector, but successful exploitation could affect confidentiality, integrity, and availability. It is rated 6.8 under CVSS v3.1 and 7.0 under CVSS v4.0.
Worldwide deployments face confidentiality and control risks
CISA places the affected product in the Commercial Facilities sector and says it is deployed worldwide. Anjvision is headquartered in China.
The practical consequences depend on which interface an attacker can reach and whether credentials are already available. Possible outcomes include disclosure of account information, internal-network reconnaissance, password resets, unauthorized firmware installation, command execution, and full device control.
Internet-exposed systems face the clearest immediate risk because several flaws are remotely reachable and two require no authentication. Low-privileged users can also trigger multiple high-impact conditions, including the debug-command pathway and administrator-password reset.
Andrew Lee reported the vulnerabilities to CISA. It is not known whether attackers have exploited any of them in operational environments, and no device-specific indicators of compromise have been published.
The available information does not identify any of these vulnerabilities as entries in CISA’s Known Exploited Vulnerabilities catalog. Consequently, no KEV remediation deadline or ransomware-use flag has been reported.
No patch is planned, making exposure reduction the primary defense
CISA reports that no fix is planned. There is no firmware update or vulnerability-specific workaround available, and Anjvision did not engage with CISA on mitigation. Customers are directed to contact Anjvision support for further information.
Until a supported correction becomes available, organizations should identify every YSSD-RTMP-H5 device and verify its firmware. Systems running 3.3.2.4_build_2024-12-26 should be treated as vulnerable.
Operators should then apply compensating controls:
- Remove direct internet access to the device and its management interfaces.
- Place video and control-system equipment behind firewalls.
- Separate affected devices from business networks and sensitive internal services.
- Restrict ONVIF, web management, SOAP-RPC, update, and cloud-related traffic to necessary systems.
- Allow remote administration only through maintained, appropriately secured VPN infrastructure.
- Review device accounts, administrator-password changes, firmware-update activity, and unexpected debug-interface behavior.
- Monitor DNS and outbound connections for unexplained requests originating from affected devices.
No product-specific compromise indicators are available, so monitoring must focus on behavioral anomalies and unauthorized configuration changes. Organizations should conduct an impact and risk assessment before applying network restrictions, particularly where the devices support safety, surveillance, or operational processes.
Sources
This article is an original reworking based on the sources below.
- primary sourceCVE Program
- CISA Advisories
CVEs covered in this article
- CVE-2026-100291Critical9.8In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, several ONVIF service endpoints process management requests without enforcing required authentication. This could allow an unauthorized attacker to access sensitive device operations.
- CVE-2026-100292High8.8In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, a hidden debug interface can be enabled through an authenticated request, allowing additional commands to be sent to a backend service. Once active, this pathway can unintentionally expose system‑level functionality that could be misused if crafted
- CVE-2026-100293High8.8In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, both the local and cloud update mechanisms apply new firmware without any cryptographic verification, relying only on basic hashing. This design allows an attacker who can reach the update routine to introduce untrusted firmware images that the dev
- CVE-2026-100298High8.8In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, two user‑information endpoints can reveal sensitive device and account details under conditions that are not intended for normal operation.
- CVE-2026-100296High8.1In Anjvision YSSD-RTMP-H5 firmware version 3.3.2.4, an empty-body POST to /setUserConfig, dispatched through the web server's SOAP-RPC handler, silently downgrades the administrator password to the default value and corrupts the in-memory authentication state until the device reloads. The handler do
- CVE-2026-100294High7.5In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, the firmware embeds hardcoded cloud‑API credentials that are shared across deployed devices. Anyone obtaining the public firmware package can reuse these values to interact with the cloud service in ways not intended for normal operation.
- CVE-2026-100295Medium6.3In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, an internal debug interface can be enabled through an undocumented pathway, exposing functions not intended for normal operation. When activated, this interface allows actions that could unintentionally provide elevated system access.
- CVE-2026-100297Medium5.3In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, an unauthenticated network check function can be triggered to probe arbitrary hosts from the device’s internal network. This may expose internal information or leak data via DNS queries.




