CVE-2026-100294
7.5 HIGHPublished 2026-09-29 · Updated 2026-09-29
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, the firmware embeds hardcoded cloud‑API credentials that are shared across deployed devices. Anyone obtaining the public firmware package can reuse these values to interact with the cloud service in ways not intended for normal operation.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weaknesses
CWE-798
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- HIGHCVE-2026-101052PoC
- HIGHCVE-2026-17644
- CRITICALCVE-2026-47116PoC
- MEDIUMCVE-2026-63406PoC
- CRITICALCVE-2026-65113PoC
- CRITICALCVE-2026-71238PoC
- UNSCOREDCVE-2026-7193
- CRITICALCVE-2026-76708
Related by shared AI tags and CWE weakness class. Browse the full archive.