Privilege Escalation in ANJIA IP Camera Device by Hard-Coded Credentials
CVE-2026-85083
7HIGH
What is CVE-2026-85083?
The ANJIA AJL33PC0801 IP camera contains a significant vulnerability due to the use of hard-coded credentials for bootloader authentication. This flaw allows an attacker with physical access to the device to gain unauthorized privileged access to the bootloader. Consequently, this access facilitates the manipulation of firmware and system configurations, which could lead to an entire compromise of the device's functionality and security.
Affected Version(s)
ANJIA AJL33PC0801 Firmware linux_linux_202008261138_svn13796 / Bootloader U-Boot 2010.06 (compiled 2020-08-26)
References
CVSS V4
Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Omkar Mali reported this vulnerability to CISA.
