CareCam IP Camera Bootloader Uses Hardcoded Credential
The vendor, headquartered in China, didn't respond to CISA's coordination attempts, operators are left with network isolation as the only mitigation.
TL;DR
CISA published an advisory for CVE-2026-85083, a hardcoded-credential vulnerability in the bootloader of CareCam Pro IP cameras running on ANJIA AJL33PC0801 hardware with firmware compiled August 2020. An attacker with physical access can gain privileged bootloader access and compromise the device completely, modify firmware, alter configuration, take full control. CareCam didn't respond to CISA's coordination attempts, so no vendor fix has been announced. The vulnerability isn't remotely exploitable, but organizations using these cameras in commercial facilities worldwide have no remediation path beyond network segmentation and physical access controls.
This is the kind of advisory where the CVSS score, 6.8 under v3.1, 7.0 under v4.0, understates the operational headache. The attack vector requires physical access, which keeps the number moderate. But the remediation section is one sentence long, and it amounts to: the vendor won't pick up the phone.
CareCam's silence means no firmware fix has been announced, and none should be expected on any particular timeline. CISA's standard fallback ("Users are encouraged to reach out to CareCam") lands differently when CISA itself couldn't get a reply. For any organization that has these cameras deployed across a commercial facility, the practical takeaway is that a device you already bought carries a baked-in credential that can't be removed, and the manufacturer isn't offering a path out.
The mitigation is straightforward but permanent: put the cameras on an isolated VLAN with no internet access, restrict physical access to the devices, and treat them as untrusted endpoints. If you're procuring IP cameras for a facility that falls under any compliance regime (CMMC, FedRAMP physical security controls, NIST SP 800-171) a vendor's track record of answering CISA's emails belongs on the checklist.
Published ·Deep Fathom