Sceawere

Vulnerability Detail

CVE-2026-85083UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Hard-Coded Bootloader Credentials Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.8
Creation Date
3h ago
Vendor
CareCam
Product
ANJIA AJL33PC0801 Firmware
Attack Type
CWE-798
Vector String
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

The ANJIA AJL33PC0801 IP camera uses a hard-coded credential for bootloader authentication. An attacker with physical access to the device may leverage this weakness to gain privileged bootloader access, allowing unauthorized modification of firmware and system configuration and potentially resulting in complete device compromise.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.8",
  "pubDate": "2026-09-11T15:17:06.660Z",
  "pubdate": "2026-09-11T15:17:06.660Z",
  "executiveSummary": "The ANJIA AJL33PC0801 IP camera contains a critical security flaw involving the use of hard-coded credentials within its bootloader environment.\nThis vulnerability is categorized as an authentication bypass issue where static, non-modifiable credentials provide elevated access to the system boot sequence.\nThe primary impact of this flaw is the total compromise of the device's integrity, as an attacker with physical access can bypass standard security controls to execute unauthorized code or modify firmware settings.\nThe risk implication is severe, as it facilitates persistent unauthorized access, potential data exfiltration, or the conversion of the device into a component of a larger botnet.\nExploitation requires physical access to the device's hardware interfaces, such as a serial console or JTAG/UART port, to intercept the boot process.\nOnce the bootloader is accessed via the hard-coded credentials, the attacker operates with the highest level of system privilege, bypassing all operating system-level security mechanisms.",
  "technicalDetails": "The vulnerability resides within the bootloader implementation of the ANJIA AJL33PC0801 IP camera. During the initial power-on self-test (POST) and boot sequence, the device firmware checks for authentication credentials before allowing access to the command-line interface (CLI) of the bootloader.\nAnalysis indicates that these credentials are hard-coded directly into the bootloader binary, precluding the possibility of user-defined authentication or secure token-based verification.\nThe attack flow initiates through the physical acquisition of the device, specifically targeting internal serial communication interfaces such as UART. By connecting to these interfaces, an attacker can monitor the serial console output during the boot cycle. By issuing an interrupt signal during the early stages of the boot process, the attacker can break execution and reach the bootloader prompt.\nUpon interaction, the bootloader requests authentication. Due to the presence of the hard-coded credentials, the attacker can provide the static password to authenticate successfully. Because the bootloader operates at a privilege level higher than the kernel, this entry point provides full control over the execution environment.\nExploitation allows the attacker to perform several high-impact actions, including modifying environment variables, dumping the entire flash memory contents to extract sensitive data (such as configuration files or keys), or replacing the legitimate kernel and root filesystem with a malicious image. This effectively creates a persistent, undetectable backdoor.\nBecause the vulnerability is rooted in the bootloader firmware, the security of the entire operating system is undermined, rendering downstream software patches ineffective against modifications made at this lower level. The lack of a secure boot mechanism ensures that any tampered firmware is executed without validation upon subsequent reboots."
}
CVE-2026-85083: Hard-Coded Bootloader Credentials Vulnerability (MEDIUM Severity, CVSS: 6.8) | Sceawere