OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-100291

CRITICAL · CVSS 9.8 EPSS 0.33%

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

The Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4 is vulnerable due to several ONVIF service endpoints that handle management requests without proper authentication. This critical flaw could enable unauthorized attackers to execute sensitive operations on the device, potentially compromising its integrity and security. Organizations using this firmware should prioritize immediate remediation to mitigate the risk of exploitation.

CVE
CVE-2026-100291
Severity
CRITICAL
CVSS
9.8
EPSS
0.33%

Original NVD Description

In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, several ONVIF service endpoints process management requests without enforcing required authentication. This could allow an unauthorized attacker to access sensitive device operations.