AVer PTC Cameras Hit by Critical RCE Flaw CVE-2026-40624 (CVSS 9.8)
ID: d0c52e8a-6433-555b-90af-aece7d4c9bda
STIX ID: report--d0c52e8a-6433-555b-90af-aece7d4c9bda
Feed Name: securityonline.info
CVE-2026-40624 is a critical (CVSS 9.8) remote code execution vulnerability in AVer PTC cameras (PTC500S, PTC115, PTC500+, PTC115+) allowing unauthenticated attackers to run attacker-supplied code via the device web management interface; AVer has released firmware updates and CISA published advisory ICSA-26-169-01 (June 18, 2026). Recommended mitigations include applying firmware updates, isolating cameras on a separate VLAN, blocking internet access, and restricting management access to trusted hosts; no confirmed exploitation has been reported and the EPSS is 0.6% (30-day).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
