CareCam Pro IP Cameras
Summary
A vulnerability (CVE-2026-85083) has been identified in CareCam Pro IP Cameras, specifically in the ANJIA AJL33PC0801 firmware. This vulnerability involves the use of hard-coded credentials in the bootloader, which an attacker with physical access could exploit to gain privileged access and potentially compromise the device's firmware and configuration.
IFF Assessment
The discovery of a hard-coded credential vulnerability that allows for potential full device compromise represents a significant security risk for users of the affected IP cameras.
Severity
The CVSS score of 6.8 (MEDIUM) is assigned due to the attack vector being physical (AV:P), requiring local access to the device. However, the potential impact on confidentiality, integrity, and availability (C:H/I:H/A:H) is high, indicating a severe outcome once access is gained.
Defender Context
This alert highlights the persistent risk of hard-coded credentials in IoT devices, particularly those deployed in critical infrastructure or sensitive environments. Defenders should be aware of the potential for physical attacks to bypass network-based security controls and prioritize inventorying and patching or segmenting vulnerable devices.