---
id: CVE-2026-100297
title: >-
  In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, an unauthenticated network
  check function can be triggered to probe arbitrary hosts from the device’s
  internal network
summary: >-
  In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, an unauthenticated network
  check function can be triggered to probe arbitrary hosts from the device’s
  internal network. This may expose internal information or leak data via DNS
  queries.
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-918
vendor: Anjvision
product: YSSD-RTMP-H5
affected:
  - YSSD-RTMP-H5 Version 3.3.2.4 build 2024-12-26
published: '2026-09-29'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T21:38:25.427'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-100297'
references:
  - url: 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-05'
    label: ics-cert@hq.dhs.gov
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-29T20:55:59.228871Z'
ingestedAt: '2026-09-29T20:46:06.429Z'
---

## Overview

In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, an unauthenticated network check function can be triggered to probe arbitrary hosts from the device’s internal network. This may expose internal information or leak data via DNS queries.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
