CVE-2026-100299 MEDIUM

CVE-2026-100299: Use of Weak Credentials in Anjvision YSSD-RTMP-H5

Vendor Anjvision
Product YSSD-RTMP-H5
Weakness CWE-1391
Published September 29, 2026
Last update September 29, 2026

CVSS base score

6.8/10
Attack vector Physical
Attack complexity Low
Privileges required None
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, the device includes a legacy password hash on the serial console that relies on a weak DES‑based encryption.

Key dates

02Disclosure timeline

September 29, 2026 CVE published