Research into a consumer IP camera built on Fullhan’s FH8626V100 system-on-chip uncovers a series of flaws that could allow attackers to fully compromise devices and access sensitive home network data, highlighting the risks of widely used embedded Linux platforms.
Security research into a consumer IP camera built on Fullhan’s FH8626V100 system-on-chip has exposed a chain of flaws that can lead from remote network access to full root compromise. The work, carried out on an AJL30PG0803 camera running firmware v201222.1007, shows how weak access controls, credential exposure and command injection can combine to undermine an otherwise ordinary home surveillance device. According to the advisory and subsequent reporting, the same platform is used in a wider range of rebranded cameras, which broadens the practical reach of the findings.
The technical profile of the device helps explain why the attack surface is so extensive. Fullhan’s FH8626V100 is a 32-bit embedded Linux platform with support for 1080p video input, Ethernet, audio interfaces and USB, as described in the manufacturer’s specification sheet. In this case, the camera exposed HTTP and HTTPS services, Telnet, RTSP and several custom control interfaces, including PSIA-based API endpoints and a snapshot service. That mix of legacy and bespoke services created multiple entry points for unauthenticated probing.
The research identifies six CVEs covering separate but related weaknesses. An attacker could first query a PSIA endpoint to retrieve plaintext administrative credentials, then use a crafted payload against a custom TCP service to reset the root password. With those credentials in hand, the always-on Telnet service could be used to obtain an interactive root shell. From there, the device’s configuration files could be read to recover Wi-Fi credentials and potentially move laterally into the local network. OffSec Radar’s summary of the disclosure describes the chain as fully unauthenticated until the final Telnet login, which is satisfied by the attacker’s own password reset.
The impact is serious for any camera exposed on a local network or, more dangerously, forwarded to the internet. The device owner could lose live video confidentiality, internal wireless credentials and a foothold inside the wider home or small-office network. The researcher says the vulnerabilities were discovered on 31 March 2026 and that the vendor was contacted the following day, with no response recorded in the disclosure timeline. The repository was released for defensive research and authorised testing only, but the findings underline how a single low-cost camera platform can become a route to full device takeover.
Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.





