Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 29 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 29 Sep 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, a hidden debug interface can be enabled through an authenticated request, allowing additional commands to be sent to a backend service. Once active, this pathway can unintentionally expose system‑level functionality that could be misused if crafted inputs reach the underlying command handler. | |
| Title | Improper neutralization of special elements used in an OS command ('OS command injection') in Anjvision YSSD-RTMP-H5 | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-09-29T21:01:58.854Z
Reserved: 2026-09-25T17:42:35.995Z
Link: CVE-2026-100292
Updated: 2026-09-29T20:59:59.177Z
Status : Deferred
Published: 2026-09-29T20:17:09.477
Modified: 2026-09-29T22:17:05.627
Link: CVE-2026-100292
No data.
OpenCVE Enrichment
Updated: 2026-09-29T21:45:17Z