CVE-2026-100296
HIGH
7,2
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
HIGH
8,1
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: none
Scope: unchanged
Confidentiality: none
Integrity: high
Availability: high
Description
AI Translation Available
In Anjvision YSSD-RTMP-H5 firmware version 3.3.2.4, an empty-body POST to /setUserConfig, dispatched through the web server's SOAP-RPC handler, silently downgrades the administrator password to the default value and corrupts the in-memory authentication state until the device reloads. The handler does not verify the session's privilege level, so any authenticated user can trigger it.
754
Improper Check for Unusual or Exceptional Conditions
IncompleteCommon Consequences
Security Scopes Affected:
Integrity
Availability
Potential Impacts:
Dos: Crash, Exit, Or Restart
Unexpected State
Applicable Platforms
All platforms may be affected
https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-05