CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

CareCam Pro IP Cameras

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6684

As cited

Copy frozen at (site build).

vulnerabilities

CareCam Pro IP Cameras

The ANJIA AJL33PC0801 CareCam Pro IP camera contains a hard-coded credential vulnerability (CVE-2026-85083) in its bootloader that allows an attacker with physical access to gain privileged access and modify firmware. CareCam has not responded to CISA coordination attempts, and no public exploitation has been reported. The vulnerability requires physical device access and cannot be exploited remotely.

Why it matters: Organizations deploying CareCam Pro IP cameras in commercial facilities should physically secure devices and isolate them from networks, as bootloader compromise could lead to complete device takeover and potential lateral movement into facility systems.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

CareCam Pro IP Cameras

The ANJIA AJL33PC0801 CareCam Pro IP camera contains CVE-2026-85083, a hard-coded credential vulnerability in the bootloader that allows an attacker with physical access to gain privileged bootloader access and modify firmware. CVSS v4.0 scores this at 7.0 (high severity), though exploitation requires physical device access and is not remotely exploitable. CareCam has not responded to CISA coordination attempts, and no public exploitation has been reported.

Why it matters: Facility operators and security teams managing CareCam Pro IP cameras with the affected firmware version need to physically secure these devices and contact CareCam for patched firmware, as local attackers could completely compromise the camera and its network access.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary