top of page
perceptive_background_267k.jpg

JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware 4.8.30.57701411 contain a hard-coded credentials vulnerability that allows network-adjacent attackers to ga…

Published:

30 juni 2026 om 22:00:00

Alert date:

1 juli 2026 om 18:08:11

Source:

nvd.nist.gov

Click to open the original link from this advisory

Mobile & IoT, Identity & Access, Critical Infrastructure

JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware version 4.8.30.57701411 are affected by a hard-coded credentials vulnerability (CVE-2026-58453). The vulnerability allows network-adjacent attackers to authenticate using the default admin username with an empty password via the anyka_ipc HTTP service on port 80. Once authenticated, attackers can access sensitive resources including camera snapshots, live video streams, and network configuration settings. Additionally, attackers can reach factory-level API endpoints, notably the SetMAC command, which exposes a command injection surface. The vulnerability requires no special tools or credentials beyond the known defaults, making exploitation trivial for anyone on the same network. This issue is particularly concerning for home and small business users who may deploy these cameras without additional network segmentation. The vulnerability has been documented with public writeups and is listed on multiple advisory platforms including NVD and VulnCheck.

Technical details

Mitigation steps:

Affected products:

JAIOTlink C492A-W6 Wi-Fi IP Camera firmware 4.8.30.57701411

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page