ZeroHour

Search: “bootloader”

5 stories

CareCam Pro IP Cameras

CISA advisory details hard-coded bootloader credential CVE-2026-85083 in ANJIA AJL33PC0801 CareCam Pro cameras, allowing physical-access firmware compromise.

CISA ICS advisory ICSA-26-251-01 describes CVE-2026-85083, a hard-coded credential (CWE-798) used for bootloader authentication in the ANJIA AJL33PC0801 CareCam Pro IP camera. An attacker with physical access could gain privileged bootloader access and modify firmware and configuration, potentially fully compromising the device. The flaw scores 6.8 on CVSS 3.1 (7.0 on CVSS 4.0), is not remotely exploitable, and no public exploitation has been reported. Affected firmware is linux_linux_202008261138_svn13796 with U-Boot 2010.06; the vendor is headquartered in China with worldwide deployments.

CISA Advisories · 7d agoAdvisoryCVE-2026-85083

CareCam CM2507

CISA advisory: seven flaws in CareCam CM2507 IP cameras enable unauthenticated live video access, privileged ONVIF control, credential recovery, and code execution.

CISA advisory ICSA-26-258-08 discloses seven vulnerabilities in CareCam HMT.CM2507 IP cameras running firmware v251211.1507. Issues include missing authentication for network video streaming (CVE-2026-88259, CVSS 3.1 7.5), an empty password on a privileged ONVIF account (CVE-2026-84398), weak legacy hashing of the root password (CVE-2026-85497, CVSS 4.0 9.3 critical), and cleartext storage of Wi-Fi credentials (CVE-2026-81321). Physical-access flaws allow arbitrary code execution from scripts on removable media (CVE-2026-81305) and unauthenticated bootloader access (CVE-2026-85478). The cameras are deployed worldwide in commercial facilities.

Debian 13.7 ships the fixes behind 92 security advisories, updates 106 packages

Debian 13.7 'trixie' point release bundles 92 security advisories and 106 package updates, including kernel, glibc, u-boot and qemu fixes.

Debian shipped version 13.7 of 'trixie', folding in 92 previously published security advisories and corrections to 106 source packages, including six Linux kernel advisories (DSA-6381, DSA-6393, DSA-6405, DSA-6415, DSA-6466, DSA-6477). glibc fixes a buffer overflow (CVE-2026-5928) and buffer underflow (CVE-2026-5450), with 17 packages rebuilt against the updated library; qemu carries 25 CVEs including a secure boot bypass (CVE-2026-16288), imagemagick 24, wolfssl 15 and perl 13. Boot-chain fixes include a u-boot FIT image verification bypass (CVE-2026-46728), a BOOTP/DHCP buffer overread (CVE-2024-42040), and corrected intermediate certificate verification in sbsigntool. The installer was rebuilt with kernel ABI 6.12.107+deb13, and existing systems receive the fixes through normal package mirror updates.