vuln-advisoryregulatorNewsThe Broadside2 min read

Anjvision YSSD-RTMP-H5 Hit With Nine CVEs, No Fix Coming

The advisory covers vulnerabilities up to 9.8 CVSS on firmware 3.3.2.4, and the vendor hasn't responded to CISA's coordination requests, so operators can't count on a patch.


TL;DR

CISA published ICS advisory ICSA-26-272-05 covering nine vulnerabilities in Anjvision YSSD-RTMP-H5 streaming devices running firmware 3.3.2.4. The CVEs range from unauthenticated ONVIF bypass and OS command injection to hard-coded cloud credentials, unsigned firmware updates, and an admin-password-reset via empty POST. The highest scores hit 9.8. Anjvision, headquartered in China, has not responded to CISA's coordination attempts and no fix is planned. The affected devices are deployed worldwide in the Commercial Facilities sector. Operators who can't reach the vendor for mitigations are left with the familiar grim calculus: isolate the device or accept the risk.

CISA's advisory on the Anjvision YSSD-RTMP-H5 lands in a category the ICS community knows too well: serious vulnerabilities, vendor silence, and a "no fix planned" notation that puts the operational decision entirely on the asset owner.

The nine CVEs (CVE-2026-100291 through CVE-2026-100299) cover a familiar catalog of embedded-device failures. CVE-2026-100291 (CVSS 9.8) lets an unauthenticated attacker reach ONVIF management endpoints that lack authentication. CVE-2026-100294 discloses hard-coded cloud API credentials baked into firmware and shared across devices, anyone with the firmware image can reuse them. CVE-2026-100293 (CVSS 8.8) means firmware updates are accepted without cryptographic signature verification, relying only on basic hashing. CVE-2026-100297 is an unauthenticated SSRF vector that lets an attacker probe internal hosts from the device's network position.

The most operationally nasty of the group may be CVE-2026-100296: an authenticated user sends an empty-body POST to /setUserConfig, and the admin password silently resets to the factory default. The handler doesn't check privilege level. The credential is gone until the device reloads.

CVE-2026-100292 exposes a hidden debug interface that, once activated through an authenticated request, can pass crafted inputs to a backend command handler. CVE-2026-100295 is a second debug-interface vulnerability via an undocumented pathway. The source text for CVE-2026-100298 and CVE-2026-100299 wasn't fully detailed in the CSAF excerpt, but the advisory lists both under insufficiently protected credentials and weak credentials respectively.

The vendor gap

Anjvision hasn't responded to CISA's coordination requests. The advisory's remediation field says "No fix planned" for every CVE. The only suggested path is contacting the vendor through its support page, not a reassuring option when the vendor isn't engaging with the U.S. government's ICS-CERT in the first place.

This isn't CISA's first encounter with unresponsive Chinese streaming-device manufacturers. In April 2026, CISA published ICSA-26-106-03 covering Anviz CX2 Lite, CX7, and CrossChex Standard products, also with CVSS scores up to 9.8. That advisory carried the same notation: vendor didn't respond, no fix planned.

What an operator does Monday

If YSSD-RTMP-H5 devices are on your network and you can't reach the vendor, the engineering work is network segmentation, strict ACLs, and monitoring for unexpected outbound connections, particularly given the SSRF vector in CVE-2026-100297. For devices in sensitive camera positions, the hard-coded cloud credentials in CVE-2026-100294 should push the conversation toward removal. A credential that's shared across every deployed unit and extractable from public firmware is not something you firewall your way out of.


Published ·Deep Fathom