ZeroHour

CVE-2026-85083

niche

Hard-Coded Bootloader Credential in ANJIA AJL33PC0801 IP Camera

CVSS 4.0
7.0 high
EPSS
Published
()
Modified
AI analysis

The ANJIA AJL33PC0801 IP camera ships with a hard-coded credential used to authenticate to its boot bootloader (CWE-798), so anyone who knows the built-in credential can unlock privileged bootloader access. Triggering the flaw requires physical access to the device (CVSS 4.0 attack vector: Physical), with no privileges or user interaction needed; the attacker simply uses the embedded credential at the boot stage. With privileged bootloader access, an attacker can modify the camera's firmware and system configuration, potentially achieving complete compromise of the device, including persistence across reboots via modified firmware; the CVSS 4.0 vector shows the impact is confined to the device itself (no propagation to connected systems). Affected parties are owners and operators of the ANJIA AJL33PC0801 camera; related coverage also references CareCam Pro IP cameras, but the advisory data does not specify additional confirmed models or version ranges. Exploitation status: the issue is not listed in CISA's KEV, no public proof-of-concept is known, and it carries a CVSS 4.0 base score of 7.0 (High).

What to do: No fixed firmware version is given in the available data, so check with ANJIA for an updated firmware release addressing the hard-coded bootloader credential and apply it when published. Because exploitation requires physical access, restrict physical access to deployed cameras (locked enclosures, controlled premises) and inspect physically accessible units for signs of tampering or modified firmware. If compromise is suspected, reflash the device with firmware from a trusted source, since bootloader-level tampering may not be visible from the running system.

Affected
ANJIA AJL33PC0801 IP camera
CareCam Pro IP cameras (named in related coverage; not confirmed in the advisory text)
Estimated exposure
nichelikely in the thousands of deployed units at most (single niche camera model; no public install-base figures) — No public install-base or internet-exposure scan data exists for this specific ANJIA model; it is a single consumer-grade SKU from a small vendor, and because exploitation requires physical access, the realistically affected population is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The ANJIA AJL33PC0801 IP camera uses a hard-coded credential for bootloader authentication. An attacker with physical access to the device may leverage this weakness to gain privileged bootloader access, allowing unauthorized modification of firmware and system configuration and potentially resulting in complete device compromise.

Weakness
CWE-798
Vector
CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

CareCam Pro IP Cameras

CISA advisory details hard-coded bootloader credential CVE-2026-85083 in ANJIA AJL33PC0801 CareCam Pro cameras, allowing physical-access firmware compromise.

CISA ICS advisory ICSA-26-251-01 describes CVE-2026-85083, a hard-coded credential (CWE-798) used for bootloader authentication in the ANJIA AJL33PC0801 CareCam Pro IP camera. An attacker with physical access could gain privileged bootloader access and modify firmware and configuration, potentially fully compromising the device. The flaw scores 6.8 on CVSS 3.1 (7.0 on CVSS 4.0), is not remotely exploitable, and no public exploitation has been reported. Affected firmware is linux_linux_202008261138_svn13796 with U-Boot 2010.06; the vendor is headquartered in China with worldwide deployments.

CISA Advisories · 7d agoAdvisoryCVE-2026-85083