Anjvision YSSD-RTMP-H5

9 known vulnerabilities in Anjvision YSSD-RTMP-H5, 1 critical, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-100299 CVSS 7.0 high In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, the device includes a legacy password hash on the serial console that relies on a weak…
  • CVE-2026-100298 CVSS 8.7 high In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, two user‑information endpoints can reveal sensitive device and account details under…
  • CVE-2026-100297 CVSS 6.9 medium In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, an unauthenticated network check function can be triggered to probe arbitrary hosts…
  • CVE-2026-100296 CVSS 7.2 high In Anjvision YSSD-RTMP-H5 firmware version 3.3.2.4, an empty-body POST to /setUserConfig, dispatched through the web server's SOAP-RPC…
  • CVE-2026-100295 CVSS 5.3 medium In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, an internal debug interface can be enabled through an undocumented pathway, exposing…
  • CVE-2026-100294 CVSS 8.7 high In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, the firmware embeds hardcoded cloud‑API credentials that are shared across deployed…
  • CVE-2026-100293 CVSS 8.7 high In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, both the local and cloud update mechanisms apply new firmware without any…
  • CVE-2026-100292 CVSS 8.7 high In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, a hidden debug interface can be enabled through an authenticated request, allowing…
  • CVE-2026-100291 CVSS 9.3 critical In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, several ONVIF service endpoints process management requests without enforcing required…