Vulnerability Description
JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware 4.8.30.57701411 contain a hard-coded credentials vulnerability that allows network-adjacent attackers to gain unauthorized access by using the default admin username with an empty password accepted by the anyka_ipc HTTP service on port 80. Attackers can authenticate with these hardcoded credentials to access camera snapshots, video streams, network configuration, and factory-level API endpoints including the SetMAC command injection surface.
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
- https://github.com/rwprimitives/jaiotlink-c492a-wifi-camera/blob/main/writeups/0
- https://www.amazon.com/stores/JAIOTlink/page/3B00DC41-70C3-4BAA-925C-3D222C2633D
- https://www.vulncheck.com/advisories/jaiotlink-c492a-w6-hard-coded-credentials-v
FAQ
What is CVE-2026-58453?
CVE-2026-58453 is a vulnerability with a CVSS score of 9.8 (CRITICAL). JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware 4.8.30.57701411 contain a hard-coded credentials vulnerability that allows network-adjacent attackers to gain unauthorized access by using the defa...
How severe is CVE-2026-58453?
CVE-2026-58453 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-58453?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.