Executive brief
AVer PTC series professional tracking cameras are used in government, healthcare, and commercial facilities for high-quality video capture and broadcasting. A vulnerability in these cameras allows an unauthenticated person to remotely take full control of the device by sending a malicious web request. This could lead to unauthorized surveillance, data theft, or the camera being used as a foothold to attack other parts of the corporate network.
Technical details
A critical vulnerability exists in the web management interface of several AVer PTC camera models due to improper input validation (CWE-552/CWE-20). An unauthenticated remote attacker can exploit this by sending a specially crafted HTTP request to the device. Successful exploitation allows for arbitrary code execution with high privileges, potentially leading to full system compromise. The vulnerability affects all versions of the PTC500S, PTC115, PTC500+, and PTC115+ models. A firmware update has been released by the vendor to remediate the issue.
Affected products
- AVer PTC500S All versions
- AVer PTC115 All versions
- AVer PTC500+ All versions
- AVer PTC115+ All versions
Timeline
- 2026-06-18: advisory: CISA published ICSA-26-169-01
- 2026-06-19: disclosed: NVD publication date
- 2026-06-18: patched: AVer released firmware fix