{"id":"CVE-2026-85083","title":"The ANJIA AJL33PC0801 IP camera uses a hard-coded credential for bootloader authentication","summary":"The ANJIA AJL33PC0801 IP camera uses a hard-coded credential for bootloader authentication. An attacker with physical access to the device may leverage this weakness to gain privileged bootloader access, allowing unauthorized modificatio…","severity":"medium","cvss":6.8,"cvssVector":"CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-798"],"vendor":"CareCam","product":"ANJIA AJL33PC0801 Firmware","affected":["anjia_ajl33pc0801_firmware linux_linux_202008261138_svn13796 / Bootloader U-Boot 2010.06 (compiled 2020-08-26)"],"published":"2026-09-11","updated":"2026-09-18","sourceUpdated":"2026-09-18T19:40:31.053","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-85083","references":[{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-251-01.json","label":"ics-cert@hq.dhs.gov"},{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-251-01","label":"ics-cert@hq.dhs.gov"}],"tags":["nvd","cve.org"],"epss":0.00294,"epssPercentile":0.19503,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-11T19:13:06.370352Z"},"ingestedAt":"2026-09-14T00:35:28.534Z","slug":"CVE-2026-85083","body":"## Overview\n\nThe ANJIA AJL33PC0801 IP camera uses a hard-coded credential for bootloader authentication. An attacker with physical access to the device may leverage this weakness to gain privileged bootloader access, allowing unauthorized modification of firmware and system configuration and potentially resulting in complete device compromise.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":37,"depthScoreParts":{"impact":37.4,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}