Machine-generated analysis · WAYSCloud LLM
The affected CareCam Pro IP Cameras use a hard-coded bootloader credential.
Context
The advisory concerns CareCam Pro IP Cameras, specifically the ANJIA AJL33PC0801 model with firmware linux_linux_202008261138_svn13796_/_Bootloader_U-Boot_2010.06_compiled_2020-08-26. The vulnerability allows an attacker with physical access to gain privileged bootloader access, enabling unauthorized firmware modification and system configuration changes. The device is deployed worldwide in commercial facilities, and the vendor has not responded to CISA for coordination.
Operator considerations
Check: inventory CareCam Pro IP Cameras with the specified firmware.
Successful exploitation of this vulnerability could allow an attacker to take full control of the device.
The following versions of CareCam Pro IP Cameras are affected:
ANJIA AJL33PC0801 Firmware linux_linux_202008261138_svn13796_/_Bootloader_U-Boot_2010.06_compiled_2020-08-26 (CVE-2026-85083)
Vendor
Equipment
CareCam
CareCam Pro IP Cameras
Use of Hard-coded Credentials
Critical Infrastructure Sectors: Commercial Facilities
Countries/Areas Deployed: Worldwide
Company Headquarters Location: China
The ANJIA AJL33PC0801 IP camera uses a hard-coded credential for bootloader authentication. An attacker with physical access to the device may leverage this weakness to gain privileged bootloader access, allowing unauthorized modification of firmware and system configuration and potentially resulting in complete device compromise.
CareCam Pro IP Cameras
MitigationCareCam has not r...
Read the full advisory on CISA →