Description
The ANJIA AJL33PC0801 IP camera uses a hard-coded credential for bootloader authentication. An attacker with physical access to the device may leverage this weakness to gain privileged bootloader access, allowing unauthorized modification of firmware and system configuration and potentially resulting in complete device compromise.
Published: 2026-09-11
Score: 7 High
EPSS: n/a
KEV: No
Impact: Privilege Escalation and Device Compromise
Action: Immediate Mitigation
AI Analysis

Impact

The ANJIA AJL33PC0801 firmware contains a hard‑coded credential that unlocks bootloader authentication. This flaw permits anyone who can physically reach the camera to gain privileged bootloader access, enabling the attacker to modify firmware and system configuration. Such unauthorized changes can lead to a complete takeover of the device, compromising its functionality and any data it processes.

Affected Systems

The vulnerability affects CareCam IP cameras running the ANJIA AJL33PC0801 firmware. No specific firmware version ranges are provided, so any production device running this firmware is potentially impacted.

Risk and Exploitability

The CVSS score of 7 indicates a high severity level. The EPSS score is not available, so the current likelihood of exploitation is unknown, yet the requirement for physical access reduces the attack surface. Because the flaw is not listed in CISA's KEV catalog, there is no evidence of a publicly known exploit at present. However, once physical access is achieved, the attacker can fully compromise the device, making the vulnerability severe for environments where cameras are accessible to unauthorized personnel.

Generated by OpenCVE AI on September 11, 2026 at 16:22 UTC.

Remediation

Vendor Workaround

CareCam has not responded to CISA's attempts for coordination. Users are encouraged to reach out to CareCam.


OpenCVE Recommended Actions

  • Contact CareCam to obtain an updated firmware version that removes the hard‑coded credential and install it on all affected cameras.
  • Restrict and monitor physical access to the cameras, ensuring that only authorized personnel can reach the hardware.
  • As a temporary countermeasure, disable or lock the bootloader and isolate the cameras on a separate, secure network segment to limit any potential breach impact.

Generated by OpenCVE AI on September 11, 2026 at 16:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
Description The ANJIA AJL33PC0801 IP camera uses a hard-coded credential for bootloader authentication. An attacker with physical access to the device may leverage this weakness to gain privileged bootloader access, allowing unauthorized modification of firmware and system configuration and potentially resulting in complete device compromise.
Title CareCam Pro IP Cameras Use of Hard-coded Credentials
Weaknesses CWE-798
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 7, 'vector': 'CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-09-11T14:55:58.655Z

Reserved: 2026-09-02T22:19:57.445Z

Link: CVE-2026-85083

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T15:17:06.660

Modified: 2026-09-11T15:17:06.660

Link: CVE-2026-85083

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T16:30:08Z

Weaknesses
  • CWE-798

    Use of Hard-coded Credentials