CISA Warns of Hard-Coded Bootloader Credential in CareCam Pro IP Cameras

CISA published advisory ICSA-26-251-01 disclosing CVE-2026-85083, a hard-coded bootloader credential affecting CareCam Pro IP cameras built on the ANJIA AJL33PC0801 platform, with a CVSS score of 6.8 (v3) / 7.0 (v4).

According to the advisory, an attacker with physical access to an affected camera could use the hard-coded credential to gain full control of the device. CISA noted that CareCam, a China-headquartered manufacturer, has not responded to the agency’s coordination attempts regarding the vulnerability.

Why it matters: Hard-coded credentials remain one of the most persistent and hardest-to-remediate vulnerability classes in commodity IP camera hardware, since fixing them typically requires a firmware update the vendor may never ship — especially when, as here, the manufacturer is unresponsive to coordinated disclosure. Physical security teams relying on unbranded or white-label camera hardware should treat CISA’s advisory list as a standing procurement-risk check, not a one-time read.

Source: CISA ICS Advisory ICSA-26-251-01, September 8, 2026.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *