Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-61514: Puwell IP Camera 2.x - 4.x Allows Unauthenticated Access
CVE-2026-61514 · published 1 month ago
Summary
The Puwell IP Camera firmware versions 2.x to 4.x have a security flaw that lets anyone access the camera's live video, control its movement, and restart it without needing a password. This means that anyone with access to the camera's network can potentially cause disruption or see sensitive information. To fix this, update the camera's firmware to the latest version.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| puwell technology inc. | ip camera | <= 4.x |
Original advisory text
Puwell IP Camera 2.x - 4.x Unauthenticated Access via TCP Port 23456
Puwell IP Camera firmware versions 2.x through 4.x contains an authentication bypass vulnerability that allows unauthenticated attackers to access device functions by sending protocol-conforming packets over TCP port 23456 without credentials. Attackers can exploit the unvalidated Session field in the proprietary control protocol header to access live video streams, control pan and tilt motors, activate audio functions, and remotely restart the device.
Severity
9.3
Critical
CVSS 3.1: 9.8 (NVD)
CVSS 4.0: 9.3 (NVD)
Exploitation
EPSS <1%
Type
CWE-306Missing Authentication for Critical Function
Timeline
Published4 Aug 2026
Updated25 Sep 2026
First seen4 Aug 2026
Track software like this
Free during beta