PT-2026-88450 · Carecam · Anjia Ajl33Pc0801 Firmware
CVE-2026-85083
·
Published
2026-09-08
·
Updated
2026-09-11
CVSS v3.1
6.8
Medium
| Vector | AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
🔴 CISA flags hardcoded credential flaw in CareCam Pro IP cameras deployed globally
ANJIA AJL33PC0801 IP camera (firmware linuxlinux202008261138 svn13796, U-Boot 2010.06 compiled Aug 26 2020) contains hardcoded bootloader credentials. An attacker with physical access can exploit CVE-2026-85083 to gain privileged bootloader access, modify firmware, and achieve full device compromise.
• Affected product: CareCam Pro IP Cameras
• Deployed worldwide in commercial facilities
• Company headquarters: China
• Physical access required; not remotely exploitable
• No public exploitation reported to date
CareCam has not responded to CISA coordination attempts.
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Anjia Ajl33Pc0801 Firmware