securityonline.info 8/12/2026, 1:32:49 PM · external

CVE-2026-61515: Unauthenticated Command Injection in Puwell IP Cameras, PoC Exploit Code Publicly Disclosed

CVE-2026-61515: Unauthenticated Command Injection in Puwell IP Cameras, PoC Exploit Code Publicly Disclosed
CyberSIXT Evidence Panel Source marked as original reporting

THREE critical vulnerabilities were detected today: CVE-2026-20349 (Cisco Secure Firewall), CVE-2026-68820 (Microsoft Windows), and CVE-2026-72898 (Metabase). Additionally, two serious vulnerabilities in Puwell IP cameras, CVE-2026-61514 and CVE-2026-61515, have been disclosed, both scoring 9.8 on the CVSS scale. These allow remote attackers to bypass authentication and execute commands as root.

No vendor patches are available yet, but mitigation includes blocking specific TCP ports and isolating devices from untrusted networks. Public proof-of-concept exploit code is available for both vulnerabilities.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline