Impact
An unauthenticated command injection flaw exists in the DebugShell service of Puwell IP Camera firmware versions 2.x to 4.x. The service accepts JSON payloads over TCP port 34567 without authenticating the sender or sanitizing the supplied command field, allowing a remote adversary to inject arbitrary operating system commands. Successful exploitation yields root-level code execution and total compromise of the device, enabling the attacker to modify settings, exfiltrate data, or use the camera as a pivot point within a broader network.
Affected Systems
Devices manufactured by Puwell Technology Inc. with firmware ranging from version 2.0 up to any 4.x release are affected. The vulnerability applies to all models running the affected firmware, regardless of the interface used to control the camera.
Risk and Exploitability
The CVSS score of 9.3 places it in the high severity range, and the absence of authentication means any host that can reach port 34567 can launch an attack. The EPSS score of 2% indicates a low but nonzero probability of exploitation. The flaw is not currently listed in the CISA KEV catalog, but it is publicly known. The attack requires only network connectivity to the camera and no additional credentials, making remote exploitation trivial for systems with open access to the camera’s management port.
OpenCVE Enrichment