PatchSiren cyber security CVE debrief
CVE-2026-61514 Puwell Technology Inc. CVE debrief
The Puwell IP Camera firmware versions 2.x through 4.x contain an authentication bypass vulnerability, allowing unauthenticated attackers to access device functions by sending protocol-conforming packets over TCP port 23456 without credentials. Defenders should verify exposure and implement compensating controls. This vulnerability has a CVSS score of 9.3 and is considered CRITICAL. The CVE record was published on 2026-08-04T15:16:36.810Z and has not been modified since then. The vulnerability affects Puwell IP Camera devices, and defenders responsible for these devices, network administrators, and security teams should assess exposure and implement compensating controls.
- Vendor
- Puwell Technology Inc.
- Product
- IP Camera
- CVSS
- CRITICAL 9.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-04
- Original CVE updated
- 2026-09-09
- Advisory published
- 2026-08-04
- Advisory updated
- 2026-09-09
Who should care
Defenders responsible for Puwell IP Camera devices, network administrators, and security teams should assess exposure and implement compensating controls. They should verify exposure of Puwell IP Camera firmware versions 2.x through 4.x in the environment, assess compensating controls for TCP port 23456 access, and monitor for unauthorized access attempts on TCP port 23456. Security teams should also review the supplied official advisory or CVE record to
Why it matters
CVE-2026-61514 Puwell IP Camera authentication bypass vulnerability allows unauthenticated access to device functions, requiring defenders to verify exposure and implement compensating controls.
- Verify exposure of Puwell IP Camera firmware versions 2.x through 4.x
- Assess compensating controls for TCP port 23456 access
- Monitor for unauthorized access attempts on TCP port 23456
Technical summary
The Puwell IP Camera firmware versions 2.x through 4.x contain an authentication bypass vulnerability that allows unauthenticated attackers to access device functions by sending protocol-conforming packets over TCP port 23456 without credentials. This vulnerability has a CVSS score of 9.3 and is considered CRITICAL. The vulnerability allows attackers to access live video streams, control pan and tilt motors, activate audio functions, and remotely restart the device. Defenders should prioritize verifying exposure of Puwell IP Camera firmware versions 2.x through 4.x and assessing compensating controls.
Defensive priority
Defenders should prioritize verifying exposure of Puwell IP Camera firmware versions 2.x through 4.x and assessing compensating controls, as the vulnerability allows unauthenticated access to device functions.
Recommended defensive actions
- Verify exposure of Puwell IP Camera firmware versions 2.x through 4.x in the environment
- Assess compensating controls for TCP port 23456 access
- Monitor for unauthorized access attempts on TCP port 23456
- Implement firewall rules to restrict access to TCP port 23456
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE description and source references indicate that Puwell IP Camera firmware versions 2.x through 4.x contain an authentication bypass vulnerability, allowing unauthenticated attackers to access device functions by sending protocol-conforming packets over TCP port 23456 without credentials.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-61514 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-61514
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-61514 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-61514
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://damiri.fr/fr/cve/CVE-2026-61514
-
Source reference
Unverified legacy reference
URL: https://www.puwell.com/
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/puwell-ip-camera-2-x-4-x-unauthenticated-access-via-tcp-port-23456
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.