Executive brief
The ANJIA AJL33PC0801 IP camera used in the CareCam Pro IP Cameras product line contains a hard-coded credential for bootloader authentication. An attacker with physical access to the device can exploit this weakness to gain privileged bootloader access, allowing complete unauthorized modification of firmware and system configuration, resulting in full device compromise and potential surveillance or control of the camera system.
Technical details
This vulnerability is a use of hard-coded credentials (CWE-798) in the bootloader authentication mechanism of the ANJIA AJL33PC0801 IP camera. The affected firmware is linux_linux_202008261138_svn13796_/_Bootloader_U-Boot_2010.06_compiled_2020-08-26. The attack requires physical access to the device and no network connectivity, authentication, or user interaction—only physical proximity to the bootloader interface. An attacker exploiting this can modify firmware, alter system configuration, and achieve complete device compromise. No patch or firmware update from the vendor (CareCam) has been made available; CISA reports the vendor has not responded to coordination attempts.
Affected products
- CareCam AJL33PC0801 Bootloader U-Boot 2010.06 compiled 2020-08-26 (firmware linux_linux_202008261138_svn13796)
Timeline
- 2026-09-08: disclosed: CISA ICSA-26-251-01 advisory published