An Advisory With No Vendor on the Other End
CISA has published hard-coded credentials in CareCam Pro IP cameras running 2020 firmware and U-Boot 2010.06. The vendor did not respond to coordination attempts, so there is no patch — only isolation.

CISA published ICSA-26-251-01 on 8 September covering CareCam Pro IP cameras, specifically the ANJIA AJL33PC0801 running firmware string linux_linux_202008261138_svn13796 with U-Boot 2010.06 compiled on 26 August 2020. CVE-2026-85083 is use of hard-coded credentials, CWE-798, scoring 6.8 on CVSS v3.1 and 7.0 on v4.0. The attack vector is physical rather than remote, but successful exploitation yields privileged bootloader access and device compromise. The vendor, headquartered in China, did not respond to CISA's coordination attempts, so no fix is available; the recommended mitigations are network segmentation, isolation behind firewalls, restricting internet accessibility and using VPNs where remote access is necessary. The finder is Omkar Mali and the listed sector is commercial facilities.
The sentence that makes this advisory different from the others published this month is that nobody is going to fix it. Coordinated disclosure assumes a vendor who receives the report, produces a patch and publishes it; when the vendor does not answer, the process still produces an advisory, but its only actionable content is what the asset owner can do unilaterally. That is a meaningfully different document, and it is becoming more common as the affected device population shifts from industrial vendors with product security teams towards commodity hardware sold under many names.
The dates in the firmware string are the more useful diagnostic. A bootloader compiled in 2010 and a firmware image built in August 2020, still shipping, describes a device whose software was assembled once and never revisited. Anything running a 2010 U-Boot and a Linux of that vintage carries every vulnerability found in those components since — the hard-coded credential is the finding that happened to be reported, not the extent of the problem. The realistic security posture for such a device is that its firmware is not a trustworthy artefact.
The practical consequence for industrial and commercial sites is a question about camera estates rather than about this model. Cameras are procured by facilities or security teams rather than by OT or IT, arrive under a brand that is a reseller rather than a manufacturer, and are installed on whichever network reaches the mounting point — frequently the same one that reaches a building management system or a plant network. The right action is to find out which cameras exist, what network they are on, whether they can reach the internet outbound, and whether the vendor still exists in any meaningful sense. Where the answer to the last question is no, the device is not patchable and the only remaining control is the network it sits on, which is a design decision rather than a maintenance task.