Vulnerabilities & Exploits · IoT / OT Attack

CISA Flags Anjvision Camera Takeover Flaws

CISA says nine vulnerabilities in Anjvision YSSD-RTMP-H5 firmware 3.3.2.4_build_2024-12-26 can let an attacker reach sensitive information, user accounts, OS-level commands, or full device control, and it says no fix is planned. The affected cameras are deployed worldwide in commercial facilities.

The core issue is the management plane: some ONVIF service endpoints answer requests without enforcing authentication, so an outsider who can reach the device can use functions meant for administrators. CISA also lists a hidden debug path and an update mechanism that accepts unverified firmware, which can widen the path from access to takeover.

For exposed cameras, this is not a routine patch cycle problem but a standing exposure: the device can remain reachable and controllable for as long as it stays in service. If these cameras sit on the internet or on a network that outsiders can reach, the management interface itself is part of the attack surface, not just the video feed.

1 source · Sep 29

CVEs in this update

9 CVEs

Across YSSD-RTMP-H5.

1 critical · 5 high · 3 medium · 0 low

0 in CISA KEV · 0 with EPSS above 1%

Highest severity: CVE-2026-100291 · 9.8 CRITICAL

Timeline

Sources

Part of the PlainSec briefing for 2026-09-29

Every edition of this story: CISA Flags Anjvision Camera Takeover Flaws

More from today