All CVEs View on NVD
CVE-2026-100291
CRITICAL9.8
Published 2026-09-29 · Updated 2026-09-29 · Source ics-cert@hq.dhs.gov
Description
In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, several ONVIF service endpoints process management requests without enforcing required authentication. This could allow an unauthorized attacker to access sensitive device operations.
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-1188

