---
id: CVE-2026-61514
title: >-
  Puwell IP Camera firmware versions 2.x through 4.x contains an authentication
  bypass vulnerability that allows unauthenticated attackers to access device
  functions by sending protocol-conforming packets over TCP port 23456 without
  creden…
summary: >-
  Puwell IP Camera firmware versions 2.x through 4.x contains an authentication
  bypass vulnerability that allows unauthenticated attackers to access device
  functions by sending protocol-conforming packets over TCP port 23456 without
  creden…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-306
published: '2026-08-04'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T20:35:08.537'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-61514'
references:
  - url: 'https://damiri.fr/fr/cve/CVE-2026-61514'
    label: disclosure@vulncheck.com
  - url: 'https://www.puwell.com/'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/puwell-ip-camera-2-x-4-x-unauthenticated-access-via-tcp-port-23456
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00461
epssPercentile: 0.39272
ingestedAt: '2026-09-09T21:22:45.522Z'
---

## Overview

Puwell IP Camera firmware versions 2.x through 4.x contains an authentication bypass vulnerability that allows unauthenticated attackers to access device functions by sending protocol-conforming packets over TCP port 23456 without credentials. Attackers can exploit the unvalidated Session field in the proprietary control protocol header to access live video streams, control pan and tilt motors, activate audio functions, and remotely restart the device.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
