Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-85083— CareCam Pro IP Cameras Use of Hard-coded Credentials

Quick assessment

Affected
CareCam ANJIA AJL33PC0801 Firmware
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

安技安(ANJIA)AJL33PC0801 网络摄像头在引导加载程序(bootloader)认证中使用了硬编码的凭据。拥有设备物理访问权限的攻击者可利用此弱点获取具有权限的引导加载程序访问权,从而实现对固件和系统配置的未授权修改,并可能导致设备被完全攻陷。

CVSS 6.8 · Medium

Possible ATT&CK Techniques 1 AI

T1070 · Indicator Removal

Affected Version Matrix 1

VendorProduct Version RangeStatus
CareCam ANJIA AJL33PC0801 Firmware linux_linux_202008261138_svn13796 / Bootloader U-Boot 2010.06 (compiled 2020-08-26) affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-85083

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
CareCam Pro IP Cameras Use of Hard-coded Credentials
Source: CVE Program / CVE List V5
Vulnerability Description
The ANJIA AJL33PC0801 IP camera uses a hard-coded credential for bootloader authentication. An attacker with physical access to the device may leverage this weakness to gain privileged bootloader access, allowing unauthorized modification of firmware and system configuration and potentially resulting in complete device compromise.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
使用硬编码的凭证
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
CareCam ANJIA AJL33PC0801 Firmware linux_linux_202008261138_svn13796 / Bootloader U-Boot 2010.06 (compiled 2020-08-26) -

II. Public POCs for CVE-2026-85083

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-85083

登录查看更多情报信息。

Vendor Advisories for CVE-2026-85083 (2)

IV. Related Vulnerabilities

V. Comments for CVE-2026-85083

No comments yet


Leave a comment