CVE-2026-85083: CareCam Pro IP Cameras Use of Hard-coded Credentials
The ANJIA AJL33PC0801 IP camera uses a hard-coded credential for bootloader authentication. An attacker with physical access to the device may leverage this weakness to gain privileged bootloader access, allowing unauthorized modification of firmware and system configuration and potentially resulting in complete device compromise.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Change the bootloader authentication credential so it is not a hard-coded value (use a unique, per-device credential for bootloader authentication).
ANJIA AJL33PC0801 IP camera bootloader authentication hard-coded credential = replace/avoid hard-coded credential - Compensating control
Restrict physical access to the ANJIA AJL33PC0801 IP camera (e.g., secure the device/location so an attacker cannot access the bootloader authentication interface).
Event History
Frequently Asked Questions
Who can realistically exploit this issue?
An attacker needs physical access to an ANJIA AJL33PC0801 IP camera. The provided data does not indicate that remote network access alone is sufficient.
What level of access does exploitation provide?
The hard-coded credential can provide privileged bootloader access. This can allow unauthorized firmware and system-configuration modification and may result in complete device compromise.
Does exploitation require an existing account or user interaction?
No. The supplied severity vector indicates no privileges are required and no user interaction is required, although physical access is required.