CVE-2026-100294

In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, the firmware embeds hardcoded cloud‑API credentials that are shared across deployed devices. Anyone obtaining the public firmware package can reuse these values to interact with the cloud service in ways not intended for normal operation.

  • Published Sep 29, 2026
  • CVSS 8.7 high
  • 0.2% chance of exploitation in the next 30 days (EPSS)

Affected software

In the news

CVE-2026-100294 at the National Vulnerability Database