


Perceptive Security
SOC/SIEM Consultancy

JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware 4.8.30.57701411 contain a hard-coded credentials vulnerability that allows network-adjacent attackers to ga…
Published:
30 juni 2026 om 22:00:00
Alert date:
1 juli 2026 om 18:08:11
Source:
nvd.nist.gov
Mobile & IoT, Identity & Access, Critical Infrastructure
JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware version 4.8.30.57701411 are affected by a hard-coded credentials vulnerability (CVE-2026-58453). The vulnerability allows network-adjacent attackers to authenticate using the default admin username with an empty password via the anyka_ipc HTTP service on port 80. Once authenticated, attackers can access sensitive resources including camera snapshots, live video streams, and network configuration settings. Additionally, attackers can reach factory-level API endpoints, notably the SetMAC command, which exposes a command injection surface. The vulnerability requires no special tools or credentials beyond the known defaults, making exploitation trivial for anyone on the same network. This issue is particularly concerning for home and small business users who may deploy these cameras without additional network segmentation. The vulnerability has been documented with public writeups and is listed on multiple advisory platforms including NVD and VulnCheck.
Technical details
Mitigation steps:
Affected products:
JAIOTlink C492A-W6 Wi-Fi IP Camera firmware 4.8.30.57701411
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-58453
https://github.com/rwprimitives/jaiotlink-c492a-wifi-camera/blob/main/writeups/02-default-http-credentials.md
https://www.amazon.com/stores/JAIOTlink/page/3B00DC41-70C3-4BAA-925C-3D222C2633D5?lp_asin=B0GX1BNZ78&ref_=ast_bln&store_ref=bl_ast_dp_brandlogo_sto
https://www.vulncheck.com/advisories/jaiotlink-c492a-w6-hard-coded-credentials-via-anyka-ipc
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
