CVE-2026-100295: Active debug code in Anjvision YSSD-RTMP-H5
In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, an internal debug interface can be enabled through an undocumented pathway, exposing functions not intended for normal operation. When activated, this interface allows actions that could unintentionally provide elevated system access.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The CVSS vector indicates network reachability, low attack complexity, no user interaction, and low privileges required. The undocumented pathway must be used to enable the internal debug interface.
What impact can successful exploitation have?
Once activated, the debug interface exposes functions not intended for normal operation and could unintentionally provide elevated system access. The reported impact includes low confidentiality, integrity, and availability effects.
Which firmware version is identified as affected?
The issue is reported in Anjvision YSSD-RTMP-H5 firmware version 3.3.2.4.