CVE-2026-100293
8.8 HIGHPublished 2026-09-29 · Updated 2026-09-29
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, both the local and cloud update mechanisms apply new firmware without any cryptographic verification, relying only on basic hashing. This design allows an attacker who can reach the update routine to introduce untrusted firmware images that the device will accept as valid.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-347
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- MEDIUMCVE-2025-71422PoC
- HIGHCVE-2026-102266PoC
- CRITICALCVE-2026-102268PoC
- HIGHCVE-2026-102271PoC
- HIGHCVE-2026-102272PoC
- HIGHCVE-2026-102273PoC
- UNSCOREDCVE-2026-102508
- HIGHCVE-2026-16443
Related by shared AI tags and CWE weakness class. Browse the full archive.