OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-100293

HIGH · CVSS 8.8 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

The firmware of Anjvision YSSD‑RTMP‑H5 version 3.3.2.4 is vulnerable due to the lack of cryptographic verification in its update mechanisms, allowing attackers to inject untrusted firmware. This could lead to unauthorized control over the device, potentially compromising its functionality and security. Organizations using this firmware should prioritize remediation to mitigate the risk of exploitation.

CVE
CVE-2026-100293
Severity
HIGH
CVSS
8.8
EPSS
0.18%

Original NVD Description

In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, both the local and cloud update mechanisms apply new firmware without any cryptographic verification, relying only on basic hashing. This design allows an attacker who can reach the update routine to introduce untrusted firmware images that the device will accept as valid.