Authentication Bypass in Puwell IP Camera Firmware
CVE-2026-61514
Key Information:
- Vendor
Puwell Technology Inc.
- Status
- Vendor
- CVE Published:
- 4 August 2026
Badges
What is CVE-2026-61514?
The Puwell IP Camera firmware versions 2.x through 4.x is susceptible to an authentication bypass vulnerability. By exploiting this flaw, unauthorized attackers can send conforming packets to TCP port 23456, allowing them to access the device's functionalities without needing valid credentials. This can lead to unauthorized access to live video streams, manipulation of pan and tilt motors, activation of audio functions, and the ability to remotely restart the device. This vulnerability poses a significant risk to user privacy and security.
Affected Version(s)
IP Camera 2.x <= 4.x
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
