« Back to list

Anjvision

Anjvision Yssd Rtmp H5: vulnerabilities and CVEs

Anjvision Yssd Rtmp H5 has 5 published vulnerabilities, 5 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.

CVEs5
Last 12 months5
Critical0
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-100297Medium (6.9)0.19%—Sep 29, 2026
In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, an unauthenticated network check function can be triggered to probe arbitrary hosts from the device’s internal network. This may expose internal information or leak…
CVE-2026-100296High (7.2)0.34%—Sep 29, 2026
In Anjvision YSSD-RTMP-H5 firmware version 3.3.2.4, an empty-body POST to /setUserConfig, dispatched through the web server's SOAP-RPC handler, silently downgrades the administrator password to the default value and…
CVE-2026-100295Medium (5.3)0.21%—Sep 29, 2026
In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, an internal debug interface can be enabled through an undocumented pathway, exposing functions not intended for normal operation. When activated, this interface allows…
CVE-2026-100294High (8.7)0.23%—Sep 29, 2026
In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, the firmware embeds hardcoded cloud‑API credentials that are shared across deployed devices. Anyone obtaining the public firmware package can reuse these values to…
CVE-2026-100292High (8.7)0.29%—Sep 29, 2026
In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, a hidden debug interface can be enabled through an authenticated request, allowing additional commands to be sent to a backend service. Once active, this pathway can…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1210 Exploitation of Remote Services3
  2. T1190 Exploit Public-Facing Application2
  3. T1059 Command and Scripting Interpreter1
  4. T1078 Valid Accounts1
  5. T1078.001 Default Accounts1
  6. T1090 Proxy1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Anjvision