OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-100294

HIGH · CVSS 7.5 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

The Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4 contains hardcoded cloud-API credentials that are identical across all deployed devices, allowing unauthorized access to the cloud service. This vulnerability poses a significant risk as it enables attackers to manipulate the cloud service, potentially leading to data breaches or service disruptions. Organizations using this firmware should prioritize immediate remediation to mitigate the risk of exploitation.

CVE
CVE-2026-100294
Severity
HIGH
CVSS
7.5
EPSS
0.23%

Original NVD Description

In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, the firmware embeds hardcoded cloud‑API credentials that are shared across deployed devices. Anyone obtaining the public firmware package can reuse these values to interact with the cloud service in ways not intended for normal operation.