CVE-2026-85083 PUBLISHED

CareCam Pro IP Cameras Use of Hard-coded Credentials

Assigner: icscert
Reserved: 02.09.2026 Published: 11.09.2026 Updated: 11.09.2026

The ANJIA AJL33PC0801 IP camera uses a hard-coded credential for bootloader authentication. An attacker with physical access to the device may leverage this weakness to gain privileged bootloader access, allowing unauthorized modification of firmware and system configuration and potentially resulting in complete device compromise.

Metrics

CVSS Vector: CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 7

Product Status

Vendor CareCam
Product ANJIA AJL33PC0801 Firmware
Versions Default: unaffected
  • Version linux_linux_202008261138_svn13796 / Bootloader U-Boot 2010.06 (compiled 2020-08-26) is affected

Workarounds

CareCam has not responded to CISA's attempts for coordination. Users are encouraged to reach out to CareCam.

Credits

  • Omkar Mali reported this vulnerability to CISA. finder

References

Problem Types

  • CWE-798 CWE