{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/vendors/puwell/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-61514"},{"cvss":9.8,"id":"CVE-2026-61515"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["IP Camera","IP Camera (firmware 2.x - 4.x)"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Puwell Technology Inc.","Puwell"],"content_html":"\u003cp\u003ePuwell IP Camera firmware versions 2.x through 4.x are affected by an authentication bypass vulnerability, identified as CVE-2026-61514. The flaw resides in the proprietary control protocol used by the devices, specifically in how they handle the Session field within the protocol header. An unauthenticated attacker can send crafted, protocol-conforming packets to TCP port 23456 to bypass security checks. Successful exploitation grants an attacker full control over the device, including the ability to view live video streams, manipulate pan and tilt motor functions, toggle audio recording, or force a remote device restart. This vulnerability poses a significant risk to the integrity and privacy of environments deploying these cameras, as it requires no credentials to execute.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs network reconnaissance to identify reachable Puwell IP Cameras listening on TCP port 23456.\u003c/li\u003e\n\u003cli\u003eAttacker initiates a connection to the target device on TCP port 23456.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a protocol-conforming packet for the proprietary control interface.\u003c/li\u003e\n\u003cli\u003eAttacker inserts arbitrary or malformed data into the Session field of the packet header.\u003c/li\u003e\n\u003cli\u003eThe target device fails to validate the Session identifier, granting the attacker an authenticated context.\u003c/li\u003e\n\u003cli\u003eAttacker sends follow-up command packets to interact with device functions (e.g., streaming, motor control, or rebooting).\u003c/li\u003e\n\u003cli\u003eThe device executes the commands without requiring legitimate administrative credentials.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated remote attackers to gain unauthorized access to live surveillance video, control physical camera hardware, activate audio, and cause denial-of-service through device reboots. This affects all Puwell IP Cameras running firmware versions 2.x through 4.x, potentially leading to unauthorized physical surveillance and manipulation of security infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security and infrastructure teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately segment Puwell IP Cameras from the internet and place them in a restricted management VLAN.\u003c/li\u003e\n\u003cli\u003eImplement firewall rules to block unsolicited ingress traffic on TCP port 23456 to these devices.\u003c/li\u003e\n\u003cli\u003eAudit network logs for unexpected traffic patterns targeting TCP port 23456.\u003c/li\u003e\n\u003cli\u003eCheck with the vendor (Puwell Technology Inc.) for firmware updates addressing CVE-2026-61514.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-04T15:43:54Z","date_published":"2026-08-04T15:43:50Z","id":"https://feed.craftedsignal.io/briefs/2026-08-puwell-auth-bypass/","summary":"Puwell IP Camera firmware versions 2.x through 4.x contain an authentication bypass vulnerability (CVE-2026-61514) allowing unauthenticated attackers to control device functions via TCP port 23456.","title":"Authentication Bypass in Puwell IP Camera Firmware","url":"https://feed.craftedsignal.io/briefs/2026-08-puwell-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Puwell","version":"https://jsonfeed.org/version/1.1"}