PT-2026-67719 · Puwell · Ip Camera

·

CVE-2026-61514

·

Published

2026-08-04

·

Updated

2026-08-04

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Puwell IP Camera versions 2.x through 4.x
Description An authentication bypass exists that allows unauthenticated attackers to access device functions by sending protocol-conforming packets over TCP port 23456. By exploiting the unvalidated Session field in the proprietary control protocol header, attackers can access live video streams, control pan and tilt motors, activate audio functions, and remotely restart the device.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-61514

Affected Products

Ip Camera