PT-2026-88450 · Carecam · Anjia Ajl33Pc0801 Firmware

CVE-2026-85083

·

Published

2026-09-08

·

Updated

2026-09-11

CVSS v3.1

6.8

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
🔴 CISA flags hardcoded credential flaw in CareCam Pro IP cameras deployed globally
ANJIA AJL33PC0801 IP camera (firmware linuxlinux202008261138 svn13796, U-Boot 2010.06 compiled Aug 26 2020) contains hardcoded bootloader credentials. An attacker with physical access can exploit CVE-2026-85083 to gain privileged bootloader access, modify firmware, and achieve full device compromise. • Affected product: CareCam Pro IP Cameras • Deployed worldwide in commercial facilities • Company headquarters: China • Physical access required; not remotely exploitable • No public exploitation reported to date CareCam has not responded to CISA coordination attempts.

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85083

Affected Products

Anjia Ajl33Pc0801 Firmware