CVE-2026-100291

Critique9.8Publiée le 29 septembre 2026

In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, several ONVIF service endpoints process management requests without enforcing required authentication. This could allow an unauthorized attacker to access sensitive device operations.

Score CVSS9.8 / 10CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Type de faiblesse (CWE)CWE-1188

Articles liés

This product uses the NVD API but is not endorsed or certified by the NVD.

Base de données CVE