CISA warns of hard-coded Credentials in CareCam Pro IP Cameras
CISA issued an advisory on a security flaw in CareCam Pro IP cameras, according to the agency’s notice. The issue involves a hard-coded password that lets anyone with physical access to the device take full control.
CISA issued an advisory on a security flaw in CareCam Pro IP cameras, according to the agency’s notice. The issue involves a hard-coded password that lets anyone with physical access to the device take full control.
The vulnerability affects the ANJIA AJL33PC0801 model. It’s classified as a use of hard-coded credentials, meaning the device uses a fixed password for authentication. An attacker can use this to gain privileged bootloader access, allowing unauthorized modification of firmware and system configuration. (CISA)
Omkar Mali reported this flaw to CISA. No public exploitation has been reported yet. The vulnerability isn’t exploitable remotely, so it requires physical access to the hardware.
If you run a business that uses these cameras, check if you have the ANJIA AJL33PC0801 model. CISA recommends minimizing network exposure and ensuring these devices aren’t accessible from the internet. Locate control system networks behind firewalls and isolate them from your main business network.
CareCam has not responded to CISA’s attempts for coordination. You should reach out to the vendor directly for updates or mitigation guidance. CISA reminds organizations to perform proper impact analysis before deploying defensive measures.
We think this one’s manageable if you know where your cameras are. Most small offices won’t have these devices, and those that do should know. The real risk is if someone can walk up to the box behind the front desk. Put it on your checklist, not your panic list.
Sources: CISA Cybersecurity Advisories.
30th West Technology Solutions
IT support for Antelope Valley businesses
When you call, you talk to an owner — not a call center.
Veteran-owned · Rosamond · English & Spanish