CyberRota Analysis
AI-GeneratedThe Puwell IP Camera firmware versions 2.x through 4.x is vulnerable to an unauthenticated command injection flaw that allows remote attackers to execute arbitrary OS commands via a crafted JSON payload sent to the DebugShell interface on TCP port 34567. This critical vulnerability can lead to root-level code execution and total device compromise due to insufficient authentication and input sanitization. Organizations using these IP cameras should prioritize immediate remediation to mitigate the risk of exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Puwell IP Camera firmware versions 2.x through 4.x contains an unauthenticated command injection vulnerability that allows remote attackers to execute arbitrary operating system commands by sending a crafted JSON payload to the DebugShell interface exposed on TCP port 34567. Attackers can exploit the lack of authentication and input sanitization in the binary protocol service to pass arbitrary commands directly to the underlying operating system, achieving root-level code execution and complete device compromise.