CVE-2026-61515: Puwell IP Camera Unauthenticated Command Injection
ID: a1ed541e-b304-5093-a35b-50dc0886aff9
STIX ID: report--a1ed541e-b304-5093-a35b-50dc0886aff9
Feed Name: CosmicBytez Labs
**CVE-2026-61515 — Critical unauthenticated RCE:** Puwell IP Camera firmware 2.x–4.x contains a hidden DebugShell on TCP port 34567 that accepts JSON payloads and executes the `cmd` field as root with no authentication or input validation; a public proof-of-concept exists, no vendor patch is available, and recommended mitigations include blocking port 34567 (and companion port 23456), isolating cameras on an IoT VLAN, treating internet-exposed devices as compromised, and considering device replacement.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
