The Puwell IP Camera firmware versions 2.x through 4.x contains a critical unauthenticated command injection vulnerability. This vulnerability allows remote attackers to execute arbitrary operating system commands by sending a crafted JSON payload to the DebugShell interface exposed on TCP port 34567. The vulnerability has a CVSS score of 9.3 and is classified as CRITICAL. Organizations should prioritize [truncated]
CRITICALPuwell Technology Inc.CVE published 2026-08-04
The Puwell IP Camera firmware versions 2.x through 4.x contain an authentication bypass vulnerability, allowing unauthenticated attackers to access device functions by sending protocol-conforming packets over TCP port 23456 without credentials. Defenders should verify exposure and implement compensating controls. This vulnerability has a CVSS score of 9.3 and is considered CRITICAL. The CVE record was pub [truncated]