HackerFeeds
All CVEs

CVE-2026-100291

CRITICAL9.8

Published 2026-09-29 · Updated 2026-09-29 · Source ics-cert@hq.dhs.gov

Description

In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, several ONVIF service endpoints process management requests without enforcing required authentication. This could allow an unauthorized attacker to access sensitive device operations.

CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CWE-1188
View on NVD