Skip to content
Threat Feed
critical advisory

Authentication Bypass in Puwell IP Camera Firmware

Puwell IP Camera firmware versions 2.x through 4.x contain an authentication bypass vulnerability (CVE-2026-61514) allowing unauthenticated attackers to control device functions via TCP port 23456.

What's new

  • 1. added CVE-2026-61515; ip camera version firmware 2.x - 4.x Aug 4, 15:43 via nvd

Puwell IP Camera firmware versions 2.x through 4.x are affected by an authentication bypass vulnerability, identified as CVE-2026-61514. The flaw resides in the proprietary control protocol used by the devices, specifically in how they handle the Session field within the protocol header. An unauthenticated attacker can send crafted, protocol-conforming packets to TCP port 23456 to bypass security checks. Successful exploitation grants an attacker full control over the device, including the ability to view live video streams, manipulate pan and tilt motor functions, toggle audio recording, or force a remote device restart. This vulnerability poses a significant risk to the integrity and privacy of environments deploying these cameras, as it requires no credentials to execute.

Attack Chain

  1. Attacker performs network reconnaissance to identify reachable Puwell IP Cameras listening on TCP port 23456.
  2. Attacker initiates a connection to the target device on TCP port 23456.
  3. Attacker crafts a protocol-conforming packet for the proprietary control interface.
  4. Attacker inserts arbitrary or malformed data into the Session field of the packet header.
  5. The target device fails to validate the Session identifier, granting the attacker an authenticated context.
  6. Attacker sends follow-up command packets to interact with device functions (e.g., streaming, motor control, or rebooting).
  7. The device executes the commands without requiring legitimate administrative credentials.

Impact

Successful exploitation allows unauthenticated remote attackers to gain unauthorized access to live surveillance video, control physical camera hardware, activate audio, and cause denial-of-service through device reboots. This affects all Puwell IP Cameras running firmware versions 2.x through 4.x, potentially leading to unauthorized physical surveillance and manipulation of security infrastructure.

Recommendation

Prioritized actions for security and infrastructure teams:

  • Immediately segment Puwell IP Cameras from the internet and place them in a restricted management VLAN.
  • Implement firewall rules to block unsolicited ingress traffic on TCP port 23456 to these devices.
  • Audit network logs for unexpected traffic patterns targeting TCP port 23456.
  • Check with the vendor (Puwell Technology Inc.) for firmware updates addressing CVE-2026-61514.

Immediate actions

Block ingress traffic to TCP port 23456 on perimeter firewalls for internal IP camera assets

IT Operations 24h

Mitigations

Isolate IP cameras into a dedicated, non-routable management network

immediate IT Operations

CVE-2026-61514

Indicators of compromise

1

port

TypeValue
port34567