
ACCORDING to a report from securityonline.info researchers disclosed that a critical command injection flaw affects Puwell IP cameras, allowing attackers to run arbitrary code with root privileges without authentication.
The vulnerability, tracked as CVE-2026-61515, was published alongside a public proof‑of‑concept exploit, raising the immediate risk for devices exposed to the internet.
The flaw resides in the camera’s web management interface where insufficient validation of user‑supplied data allows shell metacharacters to be injected into a system command.
With a CVSS score of 9.8 the issue can be triggered remotely by sending a crafted HTTP request to the affected device, granting the attacker full control as the root user; a related issue CVE-2026-61514 shares similar characteristics.
Puwell has not yet released a firmware update to address either CVE-2026-61515 or CVE-2026-61514, leaving owners to rely on temporary mitigations.
Security advisories recommend blocking inbound access to the cameras’ HTTP and HTTPS ports or placing the devices behind a strict network segmentation that prevents contact from untrusted networks.
Although there are no confirmed reports of the bug being used in the wild, the availability of exploit code significantly lowers the barrier for malicious actors.
Organisations that depend on these cameras for surveillance should treat the issue as actively exploitable until a patch is applied.
Defenders should first identify all Puwell models in their inventory and verify whether they are running the vulnerable firmware versions.
Where possible, disable remote administration features and enforce strong network isolation, ensuring that the cameras can only communicate with approved video management servers.
Monitoring device logs for unexpected shell commands or sudden spikes in outbound traffic can help spot compromise attempts.
Administrators are urged to subscribe to Puwell’s security notifications and apply any future firmware updates promptly, while considering replacement of end‑of‑life units that no longer receive support.