Loading market data...
← Back to CVE feed

CVE-2026-100294

HIGH CVSS 7.5 View on NVD ↗

Description

In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, the firmware embeds hardcoded cloud‑API credentials that are shared across deployed devices. Anyone obtaining the public firmware package can reuse these values to interact with the cloud service in ways not intended for normal operation.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Published: Sep 29, 2026 20:17 UTC Modified: Sep 29, 2026 22:17 UTC