CVE-2026-100291

Critica9.8Pubblicata il 29 settembre 2026

In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, several ONVIF service endpoints process management requests without enforcing required authentication. This could allow an unauthorized attacker to access sensitive device operations.

Punteggio CVSS9.8 / 10CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Tipo di debolezza (CWE)CWE-1188

Articoli correlati

This product uses the NVD API but is not endorsed or certified by the NVD.

Database CVE