VORANT. Threat Intelligence Sign in Get the full feed

Hard-coded credential flaw in CareCam Pro cameras

routine vulnerability infrastructure

CareCam Pro IP cameras use a hard-coded bootloader credential that could let a physically-present attacker fully compromise the device.

CISA published an ICS advisory detailing CVE-2026-85083, a hard-coded credential vulnerability (CWE-798) affecting CareCam Pro IP cameras built on the ANJIA AJL33PC0801 hardware platform running a specific Linux/U-Boot bootloader firmware build. The hard-coded credential protects bootloader authentication; an attacker with physical access to the device could use it to gain privileged bootloader access, enabling unauthorized firmware modification and full device compromise.

The vulnerability requires physical access and is not remotely exploitable, limiting its scope primarily to scenarios where an attacker can gain hands-on access to deployed cameras (e.g., theft, tampering, or supply-chain interdiction). CareCam, a China-headquartered vendor with worldwide deployment in the Commercial Facilities sector, has not responded to CISA's coordination attempts, so no vendor patch or firmware update is currently available. CISA recommends standard ICS network hardening (isolating devices from business networks and the internet, using VPNs for remote access) as compensating controls, though these do not address the physical-access attack vector directly. No in-the-wild exploitation has been reported.

Mentioned in this report

Vulnerabilities CVE-2026-85083

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-251-01

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free