Wednesday, September 30, 2026 Newsletter Advertise
Breaking
Cyber

CISA lists nine Anjvision YSSD-RTMP-H5 flaws with no fix planned

CISA says the worst of the nine vulnerabilities scores 9.8 and could give an attacker full control of the device, and that the vendor has not responded.

CISA lists nine Anjvision YSSD-RTMP-H5 flaws with no fix planned. Source: CISA

CISA published an advisory on September 29, 2026 describing nine vulnerabilities in Anjvision YSSD-RTMP-H5 firmware version 3.3.2.4_build_2024-12-26, the highest of which carries a CVSS v3 base score of 9.8. The agency said Anjvision has not responded to requests to work with it on mitigations, and the issues are listed as no fix planned.

What CISA found

According to CISA, successful exploitation of the vulnerabilities could allow an attacker to access sensitive information, access user accounts, execute OS-level commands, or take full control over the device.

The advisory covers CVE-2026-100291 through CVE-2026-100299, all affecting YSSD-RTMP-H5 firmware 3.3.2.4_build_2024-12-26. The listed weakness classes include initialization of a resource with an insecure default, OS command injection, improper verification of cryptographic signature, use of hard-coded credentials, active debug code, improper check for unusual or exceptional conditions, server-side request forgery, insufficiently protected credentials and use of weak credentials.

CISA said the equipment is deployed worldwide, is used in the commercial facilities critical infrastructure sector, and that the company is headquartered in China. Andrew Lee reported the vulnerabilities to CISA.

Technical details

The most severe issue, CVE-2026-100291, carries a CVSS v3.1 base score of 9.8 and a CVSS v4.0 score of 9.3. CISA said several ONVIF service endpoints process management requests without enforcing required authentication, which could allow an unauthorized attacker to access sensitive device operations.

Three issues score 8.8 under CVSS v3.1: CVE-2026-100292, a hidden debug interface enabled through an authenticated request that can reach a backend command handler; CVE-2026-100293, local and cloud update mechanisms that apply new firmware without cryptographic verification, relying only on basic hashing; and CVE-2026-100298, two user-information endpoints that can reveal sensitive device and account details.

CISA also described CVE-2026-100296, in which an empty-body POST to /setUserConfig dispatched through the web server's SOAP-RPC handler silently downgrades the administrator password to the default value and corrupts the in-memory authentication state until the device reloads. The advisory said the handler does not verify the session's privilege level, so any authenticated user can trigger it.

Other entries include hardcoded cloud-API credentials shared across deployed devices (CVE-2026-100294, 7.5), an internal debug interface reachable through an undocumented pathway (CVE-2026-100295, 6.3), an unauthenticated network check function that can probe arbitrary hosts and leak data via DNS queries (CVE-2026-100297, 5.3), and a legacy password hash on the serial console relying on weak DES-based encryption (CVE-2026-100299, 6.8).

No patch available

For each CVE, the advisory lists the remediation as "No fix planned." CISA said Anjvision has not responded to requests to work with the agency to mitigate the vulnerabilities, and that users of affected versions are invited to contact Anjvision customer support for additional information.

CISA said no known public exploitation specifically targeting these vulnerabilities has been reported to the agency at this time.

What to do

  • Minimize network exposure for all control system devices and systems, and make sure they are not accessible from the internet, CISA says.
  • Place control system networks and remote devices behind firewalls and isolate them from business networks.
  • Where remote access is needed, use more secure methods such as VPNs, keeping them updated, while recognizing that VPNs may have vulnerabilities and are only as secure as the connected devices.
  • Perform impact analysis and risk assessment before deploying any defensive measures, CISA advises.
  • Contact Anjvision customer support for additional information, as CISA says no fix is planned.
  • Follow internal procedures and report suspected malicious activity to CISA for tracking and correlation.
  • Avoid clicking links or opening attachments in unsolicited email messages to reduce exposure to social engineering.
Key facts and where they come from
  • Exploitation could give an attacker full control of the device, CISA said.
    Successful exploitation of these vulnerabilities could allow an attacker to access sensitive information, access user accounts, execute OS-level commands, or take full control over the device.
  • Nine CVEs affect YSSD-RTMP-H5 firmware 3.3.2.4_build_2024-12-26.
    YSSD-RTMP-H5 firmware 3.3.2.4_build_2024-12-26 (CVE-2026-100291, CVE-2026-100292, CVE-2026-100293, CVE-2026-100294, CVE-2026-100295, CVE-2026-100296, CVE-2026-100297, CVE-2026-100298, CVE-2026-100299)
  • The top-scoring flaw, CVE-2026-100291, involves unauthenticated ONVIF endpoints.
    several ONVIF service endpoints process management requests without enforcing required authentication. This could allow an unauthorized attacker to access sensitive device operations.
  • Firmware updates are applied without cryptographic verification.
    both the local and cloud update mechanisms apply new firmware without any cryptographic verification, relying only on basic hashing
  • An empty-body POST to /setUserConfig resets the admin password to default.
    an empty-body POST to /setUserConfig, dispatched through the web server's SOAP-RPC handler, silently downgrades the administrator password to the default value
  • The vendor has not engaged with CISA and no fix is planned.
    Anjvision has not responded to requests to work with CISA to mitigate these vulnerabilities.
  • No known exploitation has been reported to CISA.
    No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.
  • The devices are deployed worldwide in the commercial facilities sector.
    Critical Infrastructure Sectors: Commercial Facilities

    Countries/Areas Deployed: Worldwide

Read the original from CISA →

The TechUpscale Brief

The day's cyber, AI and tech news in one short email, every weekday morning. Free. Unsubscribe anytime.

I'm most interested in

More Cyber