Legacy Password Hash Vulnerability in Anjvision YSSD‑RTMP‑H5 Firmware
CVE-2026-100299
7HIGH
What is CVE-2026-100299?
The YSSD‑RTMP‑H5 firmware version 3.3.2.4 by Anjvision contains a vulnerability that exposes a legacy password hash on the serial console. This implementation utilizes a weak DES-based encryption method, making it susceptible to unauthorized access. Attackers can exploit this flaw to gain access to sensitive information through compromised passwords, thus posing a significant security risk.
Affected Version(s)
YSSD-RTMP-H5 Version 3.3.2.4 build 2024-12-26
References
CVSS V4
Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Andrew Lee reported these vulnerabilities to CISA.
