CVE-2026-61515 CRITICAL

CVE-2026-61515: Puwell IP Camera 2.x - 4.x Unauthenticated Command Injection via DebugShell

Vendor Puwell Technology Inc.
Product IP Camera
Weakness CWE-912
Published August 4, 2026
Last update August 5, 2026

CVSS base score

9.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Puwell IP Camera firmware versions 2.x through 4.x contains an unauthenticated command injection vulnerability that allows remote attackers to execute arbitrary operating system commands by sending a crafted JSON payload to the DebugShell interface exposed on TCP port 34567. Attackers can exploit the lack of authentication and input sanitization in the binary protocol service to pass arbitrary commands directly to the underlying operating system, achieving root-level code execution and complete device compromise.

Key dates

02Disclosure timeline

August 4, 2026 CVE published
August 5, 2026 Record updated