[CYBERDIGEST]
⊞ Dashboard ⚡ Intelligence 📝 Reports 📚 Global Threats 💻 Hack Lab 🗄️ Resources ⌬ 0xJerry's Lab
📡 RSS Feed
System Online

Tag

#IoT Vulnerability

articleCRITICAL 9.8

Critical Unauthenticated Command Injection Vulnerability in Puwell IP Camera Firmware

A critical vulnerability, CVE-2026-61515, with a CVSS score of 9.8, was discovered in Puwell IP Camera firmware versions 2.x through 4.x. This vulnerability allows remote attackers to execute arbitrary operating system commands without authentication by sending a crafted JSON payload to the DebugShell interface exposed on TCP port 34567. The vulnerability is caused by a lack of authentication and input sanitization in the binary protocol service, enabling attackers to achieve root-level code execution and complete device compromise. Organizations using affected firmware versions should immediately apply patches or workarounds to prevent exploitation.

Aug 5, 20261 source