mediumOther

CareCam Pro IP Camera Hard-coded Bootloader Credentials (CVE-2026-85083)

First seen Sep 9, 2026 · Updated Sep 9, 2026 · CVSS 6.8

ICSIoThard-coded-credentialsphysical-accessIP-cameraCISA-advisoryfirmwarebootloader

CareCam Pro IP Cameras (ANJIA AJL33PC0801 firmware) contain a hard-coded credential used for bootloader authentication, allowing an attacker with physical access to gain privileged bootloader access and fully compromise the device. The vendor has not responded to CISA's coordination attempts, and no patch is currently available. Exploitation requires physical access and is not remotely exploitable.

Technical Analysis

CVE-2026-85083 (CWE-798: Use of Hard-coded Credentials) affects the U-Boot 2010.06 bootloader on CareCam ANJIA AJL33PC0801 IP cameras, compiled 2020-08-26. An attacker with physical access can use the static credential to authenticate to the bootloader, enabling unauthorized firmware and configuration modification, potentially leading to full device compromise, persistent implants, or conversion into a surveillance/pivot device. CVSS v3.1 base score is 6.8 (Medium) with attack vector Physical, while CVSS v4.0 rates it 7.0 (High) due to full confidentiality, integrity, and availability impact. There is no known public exploitation at this time, and the vulnerability is not remotely exploitable. This device is a physical IoT/ICS camera and does not have a direct AI agent system impact, as exploitation requires physical access and does not expose credentials, APIs, or supply chains commonly used by AI agent frameworks.

Affected Systems

CareCam ANJIA AJL33PC0801 IP Cameras running firmware linux_linux_202008261138_svn13796 with Bootloader U-Boot 2010.06 (compiled 2020-08-26)

Indicators of Compromise

  • N/A - No specific IOCs (hashes, IPs, domains) provided; vulnerability requires physical access to device bootloader

Remediation Steps

  1. 1

    Restrict Physical Access

    Ensure physical access to CareCam Pro IP Cameras is restricted to authorized personnel only, as exploitation requires direct physical interaction with the device.

  2. 2

    Network Isolation

    Minimize network exposure for all control system devices; ensure cameras are not accessible from the internet and are placed behind firewalls on isolated network segments.

  3. 3

    Use Secure Remote Access

    When remote administration is required, use VPNs with up-to-date patching rather than direct internet exposure of camera management interfaces.

  4. 4

    Vendor Engagement

    Since CareCam has not responded to CISA's coordination attempts, organizations using affected devices should contact the vendor directly to request a security patch or replacement firmware.

  5. 5

    Device Replacement Consideration

    Given the lack of vendor response, consider replacing affected CareCam Pro IP Cameras with devices from vendors demonstrating active security support and patching practices.

CVE / Advisory IDs

CVE-2026-85083

Industries Most Exposed

Commercial FacilitiesPhysical SecuritySurveillance

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.