CVE-2026-100291EPSS p24.0%
CVE-2026-100291CVE-2026-100291
Description
In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, several ONVIF service endpoints process management requests without enforcing required authentication. This could allow an unauthorized attacker to access sensitive device operations.
Scoring
| CVSS | 9.8 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 0.33% probability of exploitation · percentile 24.0% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-29 |