Legacy Password Hash Vulnerability in Anjvision YSSD‑RTMP‑H5 Firmware
CVE-2026-100299

7HIGH

Key Information:

Vendor

Anjvision

Vendor
CVE Published:
29 September 2026

What is CVE-2026-100299?

The YSSD‑RTMP‑H5 firmware version 3.3.2.4 by Anjvision contains a vulnerability that exposes a legacy password hash on the serial console. This implementation utilizes a weak DES-based encryption method, making it susceptible to unauthorized access. Attackers can exploit this flaw to gain access to sensitive information through compromised passwords, thus posing a significant security risk.

Affected Version(s)

YSSD-RTMP-H5 Version 3.3.2.4 build 2024-12-26

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Andrew Lee reported these vulnerabilities to CISA.
.