- CISA's advisory lists nine vulnerabilities in Anjvision YSSD-RTMP-H5 firmware 3.3.2.4. The vendor has not responded to CISA and plans no fix.
- The flaws include unsigned firmware updates, shared hardcoded cloud credentials and a request that resets the administrator password.
- Owners should find these devices, remove them from internet exposure, isolate them, and plan replacement.
A security flaw with a patch is a task. A security flaw with no patch is a decision. CISA's advisory on the Anjvision YSSD-RTMP-H5 moves nine vulnerabilities from the first group into the second. The lesson here is simple. A large part of the risk of a connected device is whether its maker will still answer the phone.
What CISA published
The advisory covers firmware version 3.3.2.4 of the YSSD-RTMP-H5, built on 2024-12-26. It assigns nine CVE IDs, CVE-2026-100291 through CVE-2026-100299. For every issue, CISA lists the status as "No fix planned".
The advisory says Anjvision "has not responded to requests to work with CISA to mitigate these vulnerabilities." It sends users to Anjvision customer support. It names Commercial Facilities as the affected sector. Andrew Lee reported the flaws to CISA.
As of the advisory, CISA knows of no public attacks on these flaws. That counts only what has been reported to the agency. It does not prove that nobody is trying.
How the weaknesses fit together
Read one at a time, the entries look like a list. Read together, they describe a device with weak doors at every layer.
Some doors need no key. CISA says several ONVIF service endpoints accept management requests without any login. ONVIF is a common standard for network cameras and similar devices.
One built-in network test also works without a login. It can be told to probe other machines, and the device sends those probes from inside its own network. The advisory warns that this could reveal details of the internal network. It also warns that data could slip out through domain-name (DNS) queries.
Some keys are shared. Deployed units running this firmware share the same cloud login values, CISA says. Those values sit inside the firmware package, which is public. CISA says anyone who obtains it can use them to work with the cloud service outside normal use.
Some keys are easy to reset. An empty POST request to /setUserConfig quietly puts the administrator password back to its default value. It also corrupts the device's login state until it reloads.
The code behind that request never checks how much power the logged-in user has. So any account that can log in can send it. If the default password is known, a low-privilege account could become an administrator account. The advisory does not say whether the default is public.
The updates themselves are open. Local and cloud updates both install new firmware without cryptographic verification. They rely only on basic hashing.
A hash can catch a corrupted file. It cannot show who made the file, because anyone can compute a hash for their own image. An attacker who reaches the update routine can hand the device firmware it will accept.
The advisory lists three more problems. One is a hidden debug interface that an authenticated request can switch on. It may expose a command handler. A second debug interface sits behind an undocumented pathway. The third is a weak, DES-based password hash on the serial console. Two user-information endpoints can also reveal device and account details.
Why "no fix planned" changes the buying question
Most security programs follow a simple loop. Learn of a flaw, apply the patch, confirm. This advisory breaks the loop at step two.
The unsigned update path is the sharpest example. It is the channel a vendor would normally use to repair the device. Here, that channel accepts firmware without checking who made it.
The cost now lands on the customer, in places few contracts name. Someone must find the devices, wall them off, watch them and eventually replace them. That work falls to facilities and IT staff. They bought a device. They never agreed to take over its security.
The same lesson applies to every connected device on a purchase order. A warranty covers hardware. A typical purchase does not promise that the maker will answer a government security agency.
What CISA advises, and what to ask
CISA advises keeping control system devices off the internet. It also advises putting them behind firewalls, apart from business networks. Where remote access is needed, it suggests a VPN. It adds that a VPN is only as secure as the devices connected to it.
Leaders can turn that into five questions for their teams:
First, do we run any YSSD-RTMP-H5 units, and on which firmware version? Second, can any of them be reached from the internet today? Third, which network do they share with business systems? Fourth, have we contacted Anjvision support, and what did they say? Fifth, what would replacement cost, and by when?
Add one rule to procurement. Before buying any connected device, ask the vendor in writing how it handles security reports. Ask how long it will ship signed updates.
A device that cannot be repaired is not yet a security incident. It becomes one when the plan for it is still undecided.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: CISA.





