---
id: CVE-2026-85083
title: >-
  The ANJIA AJL33PC0801 IP camera uses a hard-coded credential for bootloader
  authentication
summary: >-
  The ANJIA AJL33PC0801 IP camera uses a hard-coded credential for bootloader
  authentication. An attacker with physical access to the device may leverage
  this weakness to gain privileged bootloader access, allowing unauthorized
  modificatio…
severity: medium
cvss: 6.8
cvssVector: 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-798
vendor: CareCam
product: ANJIA AJL33PC0801 Firmware
affected:
  - >-
    anjia_ajl33pc0801_firmware linux_linux_202008261138_svn13796 / Bootloader
    U-Boot 2010.06 (compiled 2020-08-26)
published: '2026-09-11'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T19:40:31.053'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-85083'
references:
  - url: >-
      https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-251-01.json
    label: ics-cert@hq.dhs.gov
  - url: 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-251-01'
    label: ics-cert@hq.dhs.gov
tags:
  - nvd
  - cve.org
epss: 0.00294
epssPercentile: 0.19588
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-11T19:13:06.370352Z'
ingestedAt: '2026-09-14T00:35:28.534Z'
---

## Overview

The ANJIA AJL33PC0801 IP camera uses a hard-coded credential for bootloader authentication. An attacker with physical access to the device may leverage this weakness to gain privileged bootloader access, allowing unauthorized modification of firmware and system configuration and potentially resulting in complete device compromise.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
