Jaiotlink · C492A-W6 Wi-Fi Ip Camera · CVE-2026-58453
**Name of the Vulnerable Software and Affected Versions**
JAIOTlink C492A-W6 Wi-Fi IP camera version 4.8.30.57701411
**Description**
The anyka ipc HTTP service on port 80 accepts a default admin username with an empty password. This allows network-adjacent attackers to gain unauthorized access to camera snapshots, video streams, and network configuration. Additionally, attackers can access factory-level API endpoints, including the `SetMAC` command injection surface, which allows the execution of arbitrary commands on the system.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.