CVE-2026-100291: Anjvision Yssd-Rtmp-h5
Critical severity, CVSS 9.8. EPSS: 0.3% chance of exploitation in the next 30 days.
In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, several ONVIF service endpoints process management requests without enforcing required authentication. This could allow an unauthorized attacker to access sensitive device operations.
Affected products
- Anjvision Yssd-Rtmp-h5: version 3.3.2.4 build 2024-12-26 only
Published 2026-09-29. Last modified 2026-09-29.