Description
Puwell IP Camera firmware versions 2.x through 4.x contains an unauthenticated command injection vulnerability that allows remote attackers to execute arbitrary operating system commands by sending a crafted JSON payload to the DebugShell interface exposed on TCP port 34567. Attackers can exploit the lack of authentication and input sanitization in the binary protocol service to pass arbitrary commands directly to the underlying operating system, achieving root-level code execution and complete device compromise.
Published: 2026-08-04
Score: 9.3 Critical
EPSS: 1.6% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated command injection flaw exists in the DebugShell service of Puwell IP Camera firmware versions 2.x to 4.x. The service accepts JSON payloads over TCP port 34567 without authenticating the sender or sanitizing the supplied command field, allowing a remote adversary to inject arbitrary operating system commands. Successful exploitation yields root-level code execution and total compromise of the device, enabling the attacker to modify settings, exfiltrate data, or use the camera as a pivot point within a broader network.

Affected Systems

Devices manufactured by Puwell Technology Inc. with firmware ranging from version 2.0 up to any 4.x release are affected. The vulnerability applies to all models running the affected firmware, regardless of the interface used to control the camera.

Risk and Exploitability

The CVSS score of 9.3 places it in the high severity range, and the absence of authentication means any host that can reach port 34567 can launch an attack. The EPSS score of 2% indicates a low but nonzero probability of exploitation. The flaw is not currently listed in the CISA KEV catalog, but it is publicly known. The attack requires only network connectivity to the camera and no additional credentials, making remote exploitation trivial for systems with open access to the camera’s management port.

Generated by OpenCVE AI on August 5, 2026 at 14:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Puwell firmware that removes the DebugShell feature or patches the command injection issue.
  • If an update is not immediately available, block TCP port 34567 on the camera using the device’s firewall or a network security device to deny external access.
  • Restrict network reachability to the camera by placing it in a segmented VLAN and applying ACLs that allow management traffic only from trusted sources.

Generated by OpenCVE AI on August 5, 2026 at 14:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Puwell Technology
Puwell Technology ip Camera
Vendors & Products Puwell Technology
Puwell Technology ip Camera

Tue, 04 Aug 2026 15:00:00 +0000

Type Values Removed Values Added
Description Puwell IP Camera firmware versions 2.x through 4.x contains an unauthenticated command injection vulnerability that allows remote attackers to execute arbitrary operating system commands by sending a crafted JSON payload to the DebugShell interface exposed on TCP port 34567. Attackers can exploit the lack of authentication and input sanitization in the binary protocol service to pass arbitrary commands directly to the underlying operating system, achieving root-level code execution and complete device compromise.
Title Puwell IP Camera 2.x - 4.x Unauthenticated Command Injection via DebugShell
Weaknesses CWE-912
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Puwell Technology Ip Camera
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-05T13:16:27.502Z

Reserved: 2026-07-10T15:43:36.627Z

Link: CVE-2026-61515

cve-icon Vulnrichment

Updated: 2026-08-04T19:44:47.585Z

cve-icon NVD

Status : Received

Published: 2026-08-04T15:16:36.967

Modified: 2026-08-05T14:17:08.690

Link: CVE-2026-61515

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T14:45:16Z

Weaknesses