CVE-2026-100292: Improper neutralization of special elements used in an OS command ('OS command injection') in Anjvision YSSD-RTMP-H5
Published Sep 29, 2026
·Updated
In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, a hidden debug interface can be enabled through an authenticated request, allowing additional commands to be sent to a backend service. Once active, this pathway can unintentionally expose system‑level functionality that could be misused if crafted inputs reach the underlying command handler.
Affected Software
1 affected component
Anjvision YSSD-RTMP-H5=3.3.2.4
Event History
Sep 29, 2026
CVE Published
via MITRE·07:35 PM
Data Sourced
via MITRE·07:35 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The debug interface is enabled through an authenticated request, so an attacker needs authenticated access to send that request and use the resulting pathway.
2
Which systems are identified as affected?
The issue is identified in Anjvision YSSD-RTMP-H5 firmware version 3.3.2.4. The provided information does not state whether other firmware versions are affected.