CISA has published a security advisory warning that certain CareCam Pro IP cameras contain a hard-coded credential that could let an attacker with physical access take full control of the device. The vulnerability, tracked as CVE-2026-85083, affects the ANJIA AJL33PC0801 camera running firmware linux_linux_202008261138_svn13796 with bootloader U-Boot 2010.06 compiled on 2020-08-26.
The issue stems from a hard-coded credential used for bootloader authentication, which an attacker could exploit to gain privileged access, modify firmware and system configuration, and potentially compromise the device completely. CISA rates the vulnerability with a CVSS v3.1 base score of 6.8 (medium) and a CVSS v4.0 score of 7 (high). The vulnerability is not exploitable remotely and requires physical access to the camera.
The advisory lists the affected product as CareCam Pro IP Cameras, with the vendor identified as CareCam and the company headquarters located in China. The cameras are deployed worldwide in the Commercial Facilities critical infrastructure sector. CISA notes that CareCam has not responded to its attempts to coordinate on the vulnerability, and it encourages users to contact the vendor directly.
CISA recommends that users minimize network exposure for control system devices, isolate them from business networks, and use secure remote access methods such as VPNs when needed. The agency also advises organizations to perform impact analysis and risk assessment before deploying defensive measures. No known public exploitation of this vulnerability has been reported to CISA at this time.
The vulnerability was reported to CISA by Omkar Mali. The advisory was initially released on September 8, 2026.













