{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/vulnerability-disclosure/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Anjvision YSSD-RTMP-H5 (firmware 3.3.2.4_build_2024-12-26)"],"_cs_severities":["critical"],"_cs_tags":["critical-infrastructure","remote-access","iot","vulnerability-disclosure"],"_cs_type":"advisory","_cs_vendors":["Anjvision"],"content_html":"\u003cp\u003eThe Anjvision YSSD-RTMP-H5 device, commonly deployed in commercial facilities globally, contains multiple critical security vulnerabilities within firmware version 3.3.2.4_build_2024-12-26. These flaws, tracked as CVE-2026-100291 through CVE-2026-100299, collectively enable a range of malicious activities including unauthenticated access to device management, command injection, and firmware manipulation. The vulnerabilities stem from systemic security weaknesses such as insecure default configurations, lack of cryptographic verification for firmware updates, and the presence of hard-coded credentials and active debug interfaces. Anjvision has not provided a patch or remediation plan for these issues. Defenders should treat these devices as compromised if internet-exposed and prioritize network-level isolation or restrictive firewalling, as there is currently no path to secure the devices through vendor-provided updates.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of these vulnerabilities allows unauthenticated remote attackers to achieve OS-level command execution, intercept sensitive data, or fully take over the affected hardware. Given the deployment in commercial facilities, the impact includes potential loss of visibility, unauthorized control over physical security monitoring systems, and the ability to pivot into wider internal networks if the device is not properly segmented.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImplement strict network segmentation to ensure Anjvision YSSD-RTMP-H5 devices are not reachable from the public internet or untrusted network segments.\u003c/li\u003e\n\u003cli\u003eBlock all unsolicited inbound traffic to known management ports (e.g., ONVIF services) associated with these devices at the network perimeter.\u003c/li\u003e\n\u003cli\u003eAudit outbound traffic from these devices to prevent potential exploitation of the identified SSRF vulnerability and unauthorized cloud service interaction.\u003c/li\u003e\n\u003cli\u003eGiven the lack of vendor-provided patches, consider phasing out these devices from production environments where data integrity or system availability is critical.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-29T16:25:10Z","date_published":"2026-09-29T16:25:10Z","id":"https://feed.craftedsignal.io/briefs/2026-09-anjvision-yssd-rtmp-h5/","summary":"Anjvision YSSD-RTMP-H5 firmware version 3.3.2.4_build_2024-12-26 contains multiple critical vulnerabilities, including command injection, hard-coded credentials, and lack of firmware signing, allowing remote unauthenticated attackers to gain full system control.","title":"Multiple Critical Vulnerabilities in Anjvision YSSD-RTMP-H5 Firmware","url":"https://feed.craftedsignal.io/briefs/2026-09-anjvision-yssd-rtmp-h5/"}],"language":"en","title":"CraftedSignal Threat Feed - Vulnerability-Disclosure","version":"https://jsonfeed.org/version/1.1"}