---
id: CVE-2026-100293
title: >-
  In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, both the local and cloud
  update mechanisms apply new firmware without any cryptographic verification,
  relying only on basic hashing
summary: >-
  In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, both the local and cloud
  update mechanisms apply new firmware without any cryptographic verification,
  relying only on basic hashing. This design allows an attacker who can reach
  the upd…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-347
vendor: Anjvision
product: YSSD-RTMP-H5
affected:
  - YSSD-RTMP-H5 Version 3.3.2.4 build 2024-12-26
published: '2026-09-29'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T22:17:05.767'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-100293'
references:
  - url: 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-05'
    label: ics-cert@hq.dhs.gov
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-29T20:56:45.855256Z'
ingestedAt: '2026-09-29T20:46:06.428Z'
---

## Overview

In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, both the local and cloud update mechanisms apply new firmware without any cryptographic verification, relying only on basic hashing. This design allows an attacker who can reach the update routine to introduce untrusted firmware images that the device will accept as valid.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
