As reported by CISA in advisory ICSA-26-272-05, Anjvision's YSSD-RTMP-H5 firmware 3.3.2.4_build_2024-12-26 contains nine vulnerabilities collectively rated CVSS 9.8 Critical — and the vendor has reportedly declined to coordinate remediation. That second detail matters more than the CVSS score.
The vulnerability profile reads like a textbook of what not to do in embedded device engineering: OS command injection, hard-coded credentials, active debug code left in production, SSRF, broken cryptographic verification, and insecure default initialization. When a single device ships with flaws spanning this many CWE categories, it signals the absence of a mature secure development lifecycle rather than isolated mistakes. No patch will address that root cause.
What the Device Does and Why Exposure Matters
The YSSD-RTMP-H5 appears to be an RTMP-based streaming or surveillance appliance. Devices of this class are typically deployed as edge nodes on corporate or facility networks — often hanging off the same segments as operational technology, badge readers, and building management systems. A full device compromise in that position becomes a lateral-movement beachhead, not just a camera hijack.
| Field | Detail |
|---|---|
| Vendor | Anjvision (HQ: China) |
| Product | YSSD-RTMP-H5 |
| Affected Version | Firmware 3.3.2.4_build_2024-12-26 |
| CVEs | CVE-2026-100291, -100292, -100293, -100294, -100295, -100296, -100297, -100298, -100299 |
| CVSS v3.1 | 9.8 (Critical) — AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| CVSS v4.0 | 9.3 (Critical) |
| Patch Available | No — vendor unresponsive to CISA coordination |
| Active Exploitation | Not confirmed in the advisory, but exploit prerequisites are minimal |
The Real Story: Vendor Risk, Not Bug Risk
The vulnerabilities are severe, but the governance failure is the headline. When a manufacturer declines to patch a CVSS 9.8 product, defenders own the residual risk entirely.
Several of the listed flaws — unauthenticated ONVIF management endpoints, hard-coded credentials, and a hidden debug interface — are remotely exploitable with no user interaction. Combined with OS command injection, an attacker can pivot from network adjacency to root-level device control without ever touching a credential prompt. The attack surface is effectively the entire device.
CISA's note that Anjvision has not responded to mitigation requests places this squarely in the category of unsupported critical infrastructure components. The Commercial Facilities Sector designation means these devices may sit in environments where uptime and physical security monitoring are priorities — making unplugged-and-replace decisions operationally painful but increasingly necessary.
Supply-Chain Implications
This advisory reinforces a pattern defenders have watched for years: IoT and ICS vendors with limited security accountability producing devices that end up in sensitive deployments. For organizations performing vendor risk assessments, this episode underscores the need to evaluate not just a product's current vulnerability count but the vendor's demonstrated commitment to issuing firmware updates. A product with zero CVEs today and an unresponsive vendor is a greater long-term liability than a patched product with a transparent security history.
Shield53 Recommendations
Defenders cannot patch their way out of a vendor that refuses to engage. The only viable control here is architectural isolation followed by product replacement — and the sooner organizations begin that transition, the less likely they are to learn about these devices from an incident responder instead of an advisory.