CISA says nine vulnerabilities in Anjvision YSSD-RTMP-H5 firmware 3.3.2.4_build_2024-12-26 can let an attacker reach sensitive information, user accounts, OS-level commands, or full device control, and it says no fix is planned. The affected cameras are deployed worldwide in commercial facilities.
The core issue is the management plane: some ONVIF service endpoints answer requests without enforcing authentication, so an outsider who can reach the device can use functions meant for administrators. CISA also lists a hidden debug path and an update mechanism that accepts unverified firmware, which can widen the path from access to takeover.
For exposed cameras, this is not a routine patch cycle problem but a standing exposure: the device can remain reachable and controllable for as long as it stays in service. If these cameras sit on the internet or on a network that outsiders can reach, the management interface itself is part of the attack surface, not just the video feed.
Anjvision YSSD-RTMP-H5 Summary Successful exploitation of these vulnerabilities could allow an attacker to access sensitive information, access user accounts, execute OS-level commands, or take full control over the device.