CVE-2026-85083: CareCam Pro IP Cameras Use of Hard-coded Credentials

Published Sep 11, 2026
·
Updated

The ANJIA AJL33PC0801 IP camera uses a hard-coded credential for bootloader authentication. An attacker with physical access to the device may leverage this weakness to gain privileged bootloader access, allowing unauthorized modification of firmware and system configuration and potentially resulting in complete device compromise.

Affected Software

1 affected component
ANJIA AJL33PC0801 IP camera

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Change the bootloader authentication credential so it is not a hard-coded value (use a unique, per-device credential for bootloader authentication).

    ANJIA AJL33PC0801 IP camera bootloader authentication hard-coded credential = replace/avoid hard-coded credential
  2. Compensating control

    Restrict physical access to the ANJIA AJL33PC0801 IP camera (e.g., secure the device/location so an attacker cannot access the bootloader authentication interface).

Event History

Sep 11, 2026
CVE Published
via MITRE·02:55 PM
Data Sourced
via MITRE·02:55 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can realistically exploit this issue?

An attacker needs physical access to an ANJIA AJL33PC0801 IP camera. The provided data does not indicate that remote network access alone is sufficient.

2

What level of access does exploitation provide?

The hard-coded credential can provide privileged bootloader access. This can allow unauthorized firmware and system-configuration modification and may result in complete device compromise.

3

Does exploitation require an existing account or user interaction?

No. The supplied severity vector indicates no privileges are required and no user interaction is required, although physical access is required.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203