Impact
The vulnerability is an authentication bypass in the Puwell IP Camera firmware 2.x-4.x that allows any network actor to send protocol-conforming packets on TCP port 23456 without providing valid credentials. By exploiting the unchecked Session field in the proprietary control‑protocol header, an attacker can gain unrestricted access to critical device functions such as live video streaming, pan/tilt motor control, audio playback, and device restart. The flaw represents a classic Authentication Failure (CWE-306) and effectively removes the primary barrier to device manipulation, creating real privacy and availability risks.
Affected Systems
Affected are Puwell Technology Inc. IP Cameras running firmware versions 2.x through 4.x, all of which expose TCP port 23456 by default. No sub‑model distinctions are noted; the flaw applies broadly to every camera in that firmware range used in surveillance installations across commercial and residential environments.
Risk and Exploitability
The CVSS score of 9.3 indicates a critical severity, and the vulnerability is known to allow unauthenticated access, making it immediately exploitable. While the EPSS score is not available, the absence of a KEV listing does not diminish the risk; the attack vector is inferred to be over the local network or over the internet if port 23456 is externally reachable. Attackers can craft simple packets to establish a session and perform all device functions without any credential checks, which can lead to privacy violations or denial of service on the camera and potentially compromise other network assets.
OpenCVE Enrichment