CVE-2026-100299: Use of Weak Credentials in Anjvision YSSD-RTMP-H5
Published Sep 29, 2026
·Updated
In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, the device includes a legacy password hash on the serial console that relies on a weak DES‑based encryption.
Affected Software
1 affected component
Anjvision YSSD-RTMP-H5=3.3.2.4
Event History
Sep 29, 2026
CVE Published
via MITRE·07:52 PM
Data Sourced
via MITRE·07:52 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access would an attacker need to exploit this issue?
The weakness is present on the device's serial console, so an attacker would need access to that interface. The advisory data does not describe a network-based exploitation path.
2
Which firmware version is identified as affected?
The affected version identified is Anjvision YSSD-RTMP-H5 firmware 3.3.2.4.