Anjvision YSSD-RTMP-H5
What happened
Users of affected versions of YSSD-RTMP-H5 are invited to contact Anjvision customer support for additional information http://www.anjvision.com/problem/list-129-cn.html . Anyone obtaining the public firmware package can reuse these values to interact with the cloud service in ways not intended for normal operation.
The handler does not verify the session's privilege level, so any authenticated user can trigger it. Legal Notice and Terms of Use This product is provided subject to this Notification ( https://www.cisa.gov/notification ) and this Privacy & Use policy ( https://www.cisa.gov/privacy-policy ).
Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.
Sources & evidence
- CISA Advisories Primary / official
Anjvision YSSD-RTMP-H5 ↗
https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-05