The CISA notice, published on September 29, 2026, covers the Anjvision YSSD-RTMP-H5 and identifies nine vulnerabilities in firmware 3.3.2.4_build_2024-12-26. Reported potential impacts include access to confidential information and accounts, operating-system command execution, and full device takeover. The stated severity is critical: CVSS 3.1 of 9.8 and CVSS 4.0 of 9.3.
The described flaws include ONVIF management requests that do not require necessary authentication, a hidden debug interface, and issues such as weak or hard-coded credentials, inadequate signature validation, and command injection. The notice says the version is affected and no fix is planned; it also says the manufacturer did not respond to CISA requests to work on mitigations.
To assess exposure, inventory devices and confirm their model and firmware version with the responsible team. Compare the details with the original notice and its CSAF summary, checking the nine CVEs and severity metrics; contact the manufacturer’s support for current information. Do not assume an update is available: the source does not announce a fix.
If you use AI to summarize the notice or support an internal assessment, submit only the necessary excerpt and remove names, contact details, network addresses, credentials, and other identifying data. Keep the original in a controlled repository and check technical conclusions against the CISA notice and your security team.