Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-58453: JAIOTlink C492A-W6 IP cameras have hardcoded admin credentials
CVE-2026-58453
Summary
Some JAIOTlink C492A-W6 IP cameras have a security flaw that lets nearby hackers access the camera using a default username and an empty password. This can allow hackers to view camera footage, change the camera's network settings, and even control the camera's hardware. To fix this, update the camera's firmware to a version that doesn't have this problem.
Original title
JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware 4.8.30.57701411 contain a hard-coded credentials vulnerability that allows network-adjacent attackers to gain unauthorized access by using the d...
Original description
JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware 4.8.30.57701411 contain a hard-coded credentials vulnerability that allows network-adjacent attackers to gain unauthorized access by using the default admin username with an empty password accepted by the anyka_ipc HTTP service on port 80. Attackers can authenticate with these hardcoded credentials to access camera snapshots, video streams, network configuration, and factory-level API endpoints including the SetMAC command injection surface.
nvd CVSS3.1
9.8
nvd CVSS4.0
9.3
Vulnerability type
CWE-1392
Published: 1 Jul 2026 · Updated: 23 Jul 2026 · First seen: 1 Jul 2026