<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Vulnerability-Disclosure - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/vulnerability-disclosure/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 29 Sep 2026 16:25:10 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/vulnerability-disclosure/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Multiple Critical Vulnerabilities in Anjvision YSSD-RTMP-H5 Firmware</title><link>https://feed.craftedsignal.io/briefs/2026-09-anjvision-yssd-rtmp-h5/</link><pubDate>Tue, 29 Sep 2026 16:25:10 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-anjvision-yssd-rtmp-h5/</guid><description>Anjvision YSSD-RTMP-H5 firmware version 3.3.2.4_build_2024-12-26 contains multiple critical vulnerabilities, including command injection, hard-coded credentials, and lack of firmware signing, allowing remote unauthenticated attackers to gain full system control.</description><content:encoded><![CDATA[<p>The Anjvision YSSD-RTMP-H5 device, commonly deployed in commercial facilities globally, contains multiple critical security vulnerabilities within firmware version 3.3.2.4_build_2024-12-26. These flaws, tracked as CVE-2026-100291 through CVE-2026-100299, collectively enable a range of malicious activities including unauthenticated access to device management, command injection, and firmware manipulation. The vulnerabilities stem from systemic security weaknesses such as insecure default configurations, lack of cryptographic verification for firmware updates, and the presence of hard-coded credentials and active debug interfaces. Anjvision has not provided a patch or remediation plan for these issues. Defenders should treat these devices as compromised if internet-exposed and prioritize network-level isolation or restrictive firewalling, as there is currently no path to secure the devices through vendor-provided updates.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of these vulnerabilities allows unauthenticated remote attackers to achieve OS-level command execution, intercept sensitive data, or fully take over the affected hardware. Given the deployment in commercial facilities, the impact includes potential loss of visibility, unauthorized control over physical security monitoring systems, and the ability to pivot into wider internal networks if the device is not properly segmented.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Implement strict network segmentation to ensure Anjvision YSSD-RTMP-H5 devices are not reachable from the public internet or untrusted network segments.</li>
<li>Block all unsolicited inbound traffic to known management ports (e.g., ONVIF services) associated with these devices at the network perimeter.</li>
<li>Audit outbound traffic from these devices to prevent potential exploitation of the identified SSRF vulnerability and unauthorized cloud service interaction.</li>
<li>Given the lack of vendor-provided patches, consider phasing out these devices from production environments where data integrity or system availability is critical.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>critical-infrastructure</category><category>remote-access</category><category>iot</category><category>vulnerability-disclosure</category></item></channel></rss>