What is CVE-2026-61514?
CVE-2026-61514 is an authentication bypass vulnerability in Puwell IP Camera firmware versions 2.x through 4.x. Unauthenticated attackers can gain access to device functions by sending specially crafted packets with an invalid Session field over TCP port 23456. Recommended mitigations include isolating devices from the network, checking for firmware updates, and blocking TCP port 23456 via firewall.
Azərbaycanca: CVE-2026-61514, Puwell IP kameralarının 2.x-dən 4.x-ə qədər firmware versiyalarında autentifikasiyadan yan keçmə zəifliyidir. Təsdiqlənməmiş şəxslər TCP port 23456 üzərindən Session sahəsini yoxlamadan xüsusi paketlər göndərərək cihaz funksiyalarına icazəsiz giriş əldə edə bilərlər. Cihazları şəbəkədən təcrid etmək, firmware yeniləmələrini yoxlamaq və port 23456-nı firewall ilə bloklamaq tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
Which firmware versions of Puwell IP cameras are affected by CVE-2026-61514?
This authentication bypass vulnerability affects Puwell IP Camera firmware versions 2.x through 4.x.
How do unauthenticated attackers gain access by exploiting CVE-2026-61514?
Unauthenticated attackers can gain access to device functions by sending specially crafted packets with an invalid Session field over TCP port 23456.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.