Junglewise Threat Intelligence

CVE-2026-58453: JAIOTlink C492A-W6 hard-coded credentials in anyka_ipc service

CVE-2026-58453 · Severity: critical · CVSS 9.8 · Published 2026-07-01

Technologies: JAIOTlink C492A-W6 Wi-Fi IP Camera. Vendors: JAIOTlink.

Executive brief

JAIOTlink Wi-Fi IP cameras contain a security flaw where the device accepts a default administrator account with no password. This allows anyone on the same network to view live video streams, take snapshots, and modify the camera's network settings. Furthermore, this access can be used to reach sensitive internal tools that could allow an attacker to take full control of the device.

Technical details

The JAIOTlink C492A-W6 Wi-Fi IP camera (firmware 4.8.30.57701411) utilizes a hard-coded default credential pair (admin:[empty]) within its anyka_ipc HTTP service on port 80. This vulnerability, classified as CWE-1392, allows network-adjacent attackers to authenticate via HTTP Basic Auth without a valid password. Once authenticated, attackers can access sensitive endpoints such as /snapshot.jpg, video encoding channels, and network configuration XML files. Critically, these credentials also provide access to factory-level API endpoints, such as SetMAC, which are known to be vulnerable to command injection, potentially leading to full remote code execution. The credentials were found to be hard-coded as constants within the companion Android application, iSeeHome.

Affected products

  • JAIOTlink C492A-W6 Wi-Fi IP Camera 4.8.30.57701411

Timeline

  • 2026-07-01: advisory: Initial disclosure by VulnCheck and researcher Andres Valdes

References

Related threats