Skip to content

Security1 publisher1 min readPublished

CISA publishes nine Anjvision YSSD-RTMP-H5 flaws with no fix planned

CISA published nine flaws in Anjvision's YSSD-RTMP-H5 firmware with no fix planned, saying the vendor has not answered its requests. Owners have no patch to wait for and must isolate the devices or replace them.

The Watch · Security desk

What happened

  • Several ONVIF service endpoints on firmware 3.3.2.4 accept management requests without enforcing authentication, according to CISA.
  • The firmware embeds cloud-API credentials that are identical across deployed devices and can be recovered from the public firmware package.
  • Local and cloud firmware updates are checked only by basic hashing, so the device accepts untrusted images from anyone who can reach the update routine.
  • CISA lists the product's sector as Commercial Facilities, its deployment as worldwide, and the vendor's headquarters as China.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure Any host with a route to an affected unit's ONVIF service can send it management requests, including other machines on the same internal network.
  • exposure Pulling the shared cloud-API credential out of one firmware download gives an attacker a value that is valid for every deployed unit, not one.
  • decision A unit that may already have been reached cannot be assumed to run Anjvision's code afterward, because its updater accepts untrusted images; replacement is easier to verify than a reflash.

Ranked by what an attacker needs, the ONVIF flaw comes first because it asks for no credentials [5]. CISA files it under CWE-1188, initialization of a resource with an insecure default [5]. The command-execution flaw needs more. A hidden debug interface has to be switched on through an authenticated request before crafted input reaches the backend command handler, a CWE-78 command injection [6].

Full control of the device appears in CISA's summary of the flaws as a group, next to OS command execution, access to user accounts and exposure of sensitive information [10]. The ONVIF entry itself stops at access to "sensitive device operations" [5]. A second debug interface, enabled through an undocumented pathway, can give elevated system access, and CISA's description of that pathway does not say whether it needs a login [9].

CISA's entry on the shared cloud-API credential says it can be reused to interact with the cloud service "in ways not intended for normal operation" [8].

All nine identifiers, CVE-2026-100291 through CVE-2026-100299, are filed against one build, 3.3.2.4_build_2024-12-26 [1]. The build string carries a date of December 26, 2024 [1]. Anjvision has not responded to CISA's requests to work on mitigation, according to the advisory, and the listed remediation is "No fix planned" [3][2]. The only route CISA gives owners is Anjvision's customer support page [4].

What to watch

  • Any report of exploitation, or public proof-of-concept code, against the ONVIF endpoints or either debug interface.
  • A reply from Anjvision to CISA, or a firmware build newer than 3.3.2.4_build_2024-12-26, that changes the "No fix planned" status.
  • Research showing whether the shared cloud-API credentials reach the cloud update path; that would join two findings into a remote firmware-replacement chain.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories