top of page
perceptive_background_267k.jpg

Puwell IP Camera firmware versions 2.x through 4.x contains an authentication bypass vulnerability that allows unauthenticated attackers to access device functi…

Published:

3 August 2026 at 22:00:00

Alert date:

4 August 2026 at 16:02:00

Source:

nvd.nist.gov

Click to open the original link from this advisory

Mobile & IoT, Zero-Day Vulnerabilities, Identity & Access

Puwell IP Camera firmware versions 2.x through 4.x contains a critical authentication bypass vulnerability tracked as CVE-2026-61514. Unauthenticated attackers can exploit an unvalidated Session field in the proprietary control protocol header by sending protocol-conforming packets over TCP port 23456 without credentials. Successful exploitation allows attackers to access live video streams, control pan and tilt motors, activate audio functions, and remotely restart affected devices. The vulnerability affects a wide range of firmware versions, increasing the attack surface significantly. No authentication or special privileges are required to exploit this flaw, making it highly accessible to threat actors. The issue resides in the device's proprietary control protocol implementation, which fails to validate session credentials. This vulnerability poses significant privacy and physical security risks given the nature of IP camera devices. Patches or mitigations should be applied immediately to affected devices.

Technical details

Mitigation steps:

Affected products:

Puwell IP Camera firmware 2.x
Puwell IP Camera firmware 3.x
Puwell IP Camera firmware 4.x

Related links:

Related CVE's:

Related threat actors:

IOC's:

TCP port 23456

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page