Loading market data...
← Back to CVE feed

CVE-2026-100291

CRITICAL CVSS 9.8 View on NVD ↗

Description

In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, several ONVIF service endpoints process management requests without enforcing required authentication. This could allow an unauthorized attacker to access sensitive device operations.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Published: Sep 29, 2026 20:17 UTC Modified: Sep 29, 2026 22:17 UTC