AI analysis
The ANJIA AJL33PC0801 IP camera ships with a hard-coded credential used to authenticate to its boot bootloader (CWE-798), so anyone who knows the built-in credential can unlock privileged bootloader access. Triggering the flaw requires physical access to the device (CVSS 4.0 attack vector: Physical), with no privileges or user interaction needed; the attacker simply uses the embedded credential at the boot stage. With privileged bootloader access, an attacker can modify the camera's firmware and system configuration, potentially achieving complete compromise of the device, including persistence across reboots via modified firmware; the CVSS 4.0 vector shows the impact is confined to the device itself (no propagation to connected systems). Affected parties are owners and operators of the ANJIA AJL33PC0801 camera; related coverage also references CareCam Pro IP cameras, but the advisory data does not specify additional confirmed models or version ranges. Exploitation status: the issue is not listed in CISA's KEV, no public proof-of-concept is known, and it carries a CVSS 4.0 base score of 7.0 (High).
What to do: No fixed firmware version is given in the available data, so check with ANJIA for an updated firmware release addressing the hard-coded bootloader credential and apply it when published. Because exploitation requires physical access, restrict physical access to deployed cameras (locked enclosures, controlled premises) and inspect physically accessible units for signs of tampering or modified firmware. If compromise is suspected, reflash the device with firmware from a trusted source, since bootloader-level tampering may not be visible from the running system.
Affected
| ANJIA AJL33PC0801 IP camera | — |
| CareCam Pro IP cameras (named in related coverage; not confirmed in the advisory text) | — |
Estimated exposure
nichelikely in the thousands of deployed units at most (single niche camera model; no public install-base figures) — No public install-base or internet-exposure scan data exists for this specific ANJIA model; it is a single consumer-grade SKU from a small vendor, and because exploitation requires physical access, the realistically affected population is…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
The ANJIA AJL33PC0801 IP camera uses a hard-coded credential for bootloader authentication. An attacker with physical access to the device may leverage this weakness to gain privileged bootloader access, allowing unauthorized modification of firmware and system configuration and potentially resulting in complete device compromise.