


Perceptive Security
SOC/SIEM Consultancy

Puwell IP Camera firmware versions 2.x through 4.x contains an authentication bypass vulnerability that allows unauthenticated attackers to access device functi…
Published:
3 August 2026 at 22:00:00
Alert date:
4 August 2026 at 16:02:00
Source:
nvd.nist.gov
Mobile & IoT, Zero-Day Vulnerabilities, Identity & Access
Puwell IP Camera firmware versions 2.x through 4.x contains a critical authentication bypass vulnerability tracked as CVE-2026-61514. Unauthenticated attackers can exploit an unvalidated Session field in the proprietary control protocol header by sending protocol-conforming packets over TCP port 23456 without credentials. Successful exploitation allows attackers to access live video streams, control pan and tilt motors, activate audio functions, and remotely restart affected devices. The vulnerability affects a wide range of firmware versions, increasing the attack surface significantly. No authentication or special privileges are required to exploit this flaw, making it highly accessible to threat actors. The issue resides in the device's proprietary control protocol implementation, which fails to validate session credentials. This vulnerability poses significant privacy and physical security risks given the nature of IP camera devices. Patches or mitigations should be applied immediately to affected devices.
Technical details
Mitigation steps:
Affected products:
Puwell IP Camera firmware 2.x
Puwell IP Camera firmware 3.x
Puwell IP Camera firmware 4.x
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-61514
https://damiri.fr/fr/cve/CVE-2026-61514
https://www.puwell.com/
https://www.vulncheck.com/advisories/puwell-ip-camera-2-x-4-x-unauthenticated-access-via-tcp-port-23456
Related CVE's:
Related threat actors:
IOC's:
TCP port 23456
This article was created with the assistance of AI technology by Perceptive.
