Impact
The ANJIA AJL33PC0801 firmware contains a hard‑coded credential that unlocks bootloader authentication. This flaw permits anyone who can physically reach the camera to gain privileged bootloader access, enabling the attacker to modify firmware and system configuration. Such unauthorized changes can lead to a complete takeover of the device, compromising its functionality and any data it processes.
Affected Systems
The vulnerability affects CareCam IP cameras running the ANJIA AJL33PC0801 firmware. No specific firmware version ranges are provided, so any production device running this firmware is potentially impacted.
Risk and Exploitability
The CVSS score of 7 indicates a high severity level. The EPSS score is not available, so the current likelihood of exploitation is unknown, yet the requirement for physical access reduces the attack surface. Because the flaw is not listed in CISA's KEV catalog, there is no evidence of a publicly known exploit at present. However, once physical access is achieved, the attacker can fully compromise the device, making the vulnerability severe for environments where cameras are accessible to unauthorized personnel.
OpenCVE Enrichment