


Perceptive Security
SOC/SIEM Consultancy

Puwell IP Camera firmware versions 2.x through 4.x contains an unauthenticated command injection vulnerability that allows remote attackers to execute arbitrary…
Published:
3 August 2026 at 22:00:00
Alert date:
4 August 2026 at 16:02:00
Source:
nvd.nist.gov
Mobile & IoT, Zero-Day Vulnerabilities, Critical Infrastructure
Puwell IP Camera firmware versions 2.x through 4.x contains a critical unauthenticated command injection vulnerability tracked as CVE-2026-61515. Remote attackers can exploit the DebugShell interface exposed on TCP port 34567 by sending a crafted JSON payload. The vulnerability stems from a complete lack of authentication and input sanitization in the binary protocol service. Successful exploitation allows attackers to pass arbitrary commands directly to the underlying operating system. This results in root-level code execution and complete device compromise. No authentication is required, making this trivially exploitable by remote unauthenticated attackers. The affected firmware spans multiple major versions, indicating a wide attack surface across deployed devices.
Technical details
Mitigation steps:
Affected products:
Puwell IP Camera firmware 2.x
Puwell IP Camera firmware 3.x
Puwell IP Camera firmware 4.x
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-61515
https://damiri.fr/fr/cve/CVE-2026-61515
https://www.puwell.com/Index/catalog
https://www.vulncheck.com/advisories/puwell-ip-camera-2-x-4-x-unauthenticated-command-injection-via-debugshell
Related CVE's:
Related threat actors:
IOC's:
34567/tcp
This article was created with the assistance of AI technology by Perceptive.
