Executive brief
Puwell IP cameras contain an authentication bypass in their proprietary TCP control protocol, allowing attackers on the network to access camera functions without credentials. Unauthenticated attackers can view live video, control pan/tilt motors, activate audio, and restart devices remotely, compromising surveillance system integrity and enabling potential espionage or sabotage.
Technical details
The vulnerability is an authentication bypass in Puwell IP Camera firmware versions 2.x through 4.x. The proprietary control protocol exposed on TCP port 23456 fails to validate client credentials or session identifiers before processing commands. The protocol's Session field in the binary header is never checked, accepting any value without requiring prior authentication or session negotiation. An attacker with network access can craft protocol-conforming TCP packets to invoke privileged operations including live video stream access, PTZ (pan-tilt-zoom) motor control, audio activation, and device restart. The attack requires only network connectivity (local network or via manufacturer's P2P mechanism) and no user interaction. Patches or firmware updates have not been mentioned as available.
Affected products
- Puwell IP Camera 2.x through 4.x
Timeline
- 2026-07-14: disclosed: Vulnerability published by security researcher Yassine Damiri
- 2026-08-04: advisory: CVE-2026-61514 assigned and published on NVD