OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-100292

HIGH · CVSS 8.8 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

The Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4 contains a vulnerability that allows an authenticated user to enable a hidden debug interface, potentially exposing sensitive system-level functionality. This could lead to unauthorized command execution if malicious inputs are sent to the backend service. Organizations using this firmware should prioritize patching this vulnerability to mitigate the risk of exploitation.

CVE
CVE-2026-100292
Severity
HIGH
CVSS
8.8
EPSS
0.29%

Original NVD Description

In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, a hidden debug interface can be enabled through an authenticated request, allowing additional commands to be sent to a backend service. Once active, this pathway can unintentionally expose system‑level functionality that could be misused if crafted inputs reach the underlying command handler.