AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-61515

CRITICAL · CVSS 9.8 EPSS 1.58% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-04 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The Puwell IP Camera firmware versions 2.x through 4.x is vulnerable to an unauthenticated command injection flaw that allows remote attackers to execute arbitrary OS commands via a crafted JSON payload sent to the DebugShell interface on TCP port 34567. This critical vulnerability can lead to root-level code execution and total device compromise due to insufficient authentication and input sanitization. Organizations using these IP cameras should prioritize immediate remediation to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-61515
Severity
CRITICAL
CVSS
9.8
EPSS
1.58%

Original NVD Description

Puwell IP Camera firmware versions 2.x through 4.x contains an unauthenticated command injection vulnerability that allows remote attackers to execute arbitrary operating system commands by sending a crafted JSON payload to the DebugShell interface exposed on TCP port 34567. Attackers can exploit the lack of authentication and input sanitization in the binary protocol service to pass arbitrary commands directly to the underlying operating system, achieving root-level code execution and complete device compromise.