CVE-2026-100296: Improper Check for Unusual or Exceptional Conditions in Anjvision YSSD-RTMP-H5
In Anjvision YSSD-RTMP-H5 firmware version 3.3.2.4, an empty-body POST to /setUserConfig, dispatched through the web server's SOAP-RPC handler, silently downgrades the administrator password to the default value and corrupts the in-memory authentication state until the device reloads. The handler does not verify the session's privilege level, so any authenticated user can trigger it.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Any authenticated user can trigger it because the affected SOAP-RPC handler does not verify the session's privilege level. Network access to the device's web server and valid authentication are required.
What happens after exploitation?
An empty-body POST request to /setUserConfig causes the administrator password to be downgraded to the default value. It also corrupts the device's in-memory authentication state until the device reloads.
How can I determine whether a device is affected?
The issue is identified in Anjvision YSSD-RTMP-H5 firmware version 3.3.2.4. Affected behavior involves an empty-body POST to /setUserConfig handled through the web server's SOAP-RPC handler.