CVE-2026-100296: Improper Check for Unusual or Exceptional Conditions in Anjvision YSSD-RTMP-H5

Published Sep 29, 2026
·
Updated

In Anjvision YSSD-RTMP-H5 firmware version 3.3.2.4, an empty-body POST to /setUserConfig, dispatched through the web server's SOAP-RPC handler, silently downgrades the administrator password to the default value and corrupts the in-memory authentication state until the device reloads. The handler does not verify the session's privilege level, so any authenticated user can trigger it.

Affected Software

1 affected component
Anjvision YSSD-RTMP-H5=3.3.2.4

Event History

Sep 29, 2026
CVE Published
via MITRE·07:46 PM
Data Sourced
via MITRE·07:46 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeakness
Jul 12, 58715
Event
via NVD·11:22 AM

Frequently Asked Questions

1

Who can exploit this issue?

Any authenticated user can trigger it because the affected SOAP-RPC handler does not verify the session's privilege level. Network access to the device's web server and valid authentication are required.

2

What happens after exploitation?

An empty-body POST request to /setUserConfig causes the administrator password to be downgraded to the default value. It also corrupts the device's in-memory authentication state until the device reloads.

3

How can I determine whether a device is affected?

The issue is identified in Anjvision YSSD-RTMP-H5 firmware version 3.3.2.4. Affected behavior involves an empty-body POST to /setUserConfig handled through the web server's SOAP-RPC handler.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203