---
id: CVE-2026-100295
title: >-
  In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, an internal debug
  interface can be enabled through an undocumented pathway, exposing functions
  not intended for normal operation
summary: >-
  In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, an internal debug
  interface can be enabled through an undocumented pathway, exposing functions
  not intended for normal operation. When activated, this interface allows
  actions that coul…
severity: medium
cvss: 6.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-489
vendor: Anjvision
product: YSSD-RTMP-H5
affected:
  - YSSD-RTMP-H5 Version 3.3.2.4 build 2024-12-26
published: '2026-09-29'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T22:17:06.030'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-100295'
references:
  - url: 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-05'
    label: ics-cert@hq.dhs.gov
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-29T20:56:28.733326Z'
ingestedAt: '2026-09-29T20:46:06.429Z'
---

## Overview

In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, an internal debug interface can be enabled through an undocumented pathway, exposing functions not intended for normal operation. When activated, this interface allows actions that could unintentionally provide elevated system access.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
