CRITICAL
Puwell Technology Inc.
CVE published 2026-08-04
CVE-2026-61515
The Puwell IP Camera firmware versions 2.x through 4.x contains a critical unauthenticated command injection vulnerability. This vulnerability allows remote attackers to execute arbitrary operating system commands by sending a crafted JSON payload to the DebugShell interface exposed on TCP port 34567. The vulnerability has a CVSS score of 9.3 and is classified as CRITICAL. Organizations should prioritize [truncated]