Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-61515: Puwell IP Camera firmware allows remote attackers to execute arbitrary commands
CVE-2026-61515 · published 1 month ago
Summary
Firmware versions 2.x through 4.x of the Puwell IP Camera are vulnerable to unauthorized command execution. This means a remote attacker could potentially take control of the device and access sensitive information. Update the firmware to a secure version to protect against this risk.
Original advisory text
Puwell IP Camera firmware versions 2.x through 4.x contains an unauthenticated command injection vulnerability that allows remote attackers to execute arbitrary operating system commands by sending...
Puwell IP Camera firmware versions 2.x through 4.x contains an unauthenticated command injection vulnerability that allows remote attackers to execute arbitrary operating system commands by sending a crafted JSON payload to the DebugShell interface exposed on TCP port 34567. Attackers can exploit the lack of authentication and input sanitization in the binary protocol service to pass arbitrary commands directly to the underlying operating system, achieving root-level code execution and complete device compromise.
Severity
9.3
Critical
CVSS 3.1: 9.8 (NVD)
CVSS 4.0: 9.3 (NVD)
Exploitation
EPSS 2%
Type
CWE-912Hidden Functionality
Timeline
Published4 Aug 2026
Updated25 Sep 2026
First seen4 Aug 2026
Sources
CVE-2026-61515 · NVD
Track software like this
Free during beta