CVE-2026-100293: Improper verification of cryptographic signature in Anjvision YSSD-RTMP-H5
In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, both the local and cloud update mechanisms apply new firmware without any cryptographic verification, relying only on basic hashing. This design allows an attacker who can reach the update routine to introduce untrusted firmware images that the device will accept as valid.
Affected Software
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The attacker must be able to reach the device's firmware update routine. The available information does not specify whether that access can be obtained remotely without authentication or through a particular network exposure.
Are both local and cloud firmware updates affected?
Yes. Firmware images supplied through either the local or cloud update mechanism are applied without cryptographic signature verification.
How could I determine whether a device is affected?
Confirm that the device is an Anjvision YSSD-RTMP-H5 running firmware version 3.3.2.4. The provided information does not identify other affected firmware versions.