← Back to search

CVE-2026-61514

9.8 CRITICAL

Published 2026-08-04 · Updated 2026-08-04

AI risk analysis

Summary
The flaw allows unauthenticated attackers to access device functions by sending protocol-conforming packets over TCP port 23456, leading to unauthorized access to live video streams and control of device features.
Exploitability
Exploitation is relatively straightforward as attackers only need to send protocol-conforming packets without credentials. Precondition is access to the TCP port 23456.
Blast radius
If exploited, attackers can gain full control over the device, including accessing live video streams and controlling device functions, leading to significant privacy and security risks.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Disable the affected feature or restrict access to TCP port 23456.
auth-bypassnetworkvideo-streamingcontrol

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Puwell IP Camera firmware versions 2.x through 4.x contains an authentication bypass vulnerability that allows unauthenticated attackers to access device functions by sending protocol-conforming packets over TCP port 23456 without credentials. Attackers can exploit the unvalidated Session field in the proprietary control protocol header to access live video streams, control pan and tilt motors, activate audio functions, and remotely restart the device.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-306

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.