What is CVE-2026-61515?
CVE-2026-61515 is an unauthenticated command injection vulnerability in Puwell IP Camera firmware versions 2.x through 4.x. Remote attackers can execute arbitrary OS commands by sending a crafted JSON payload to the DebugShell interface on TCP port 34567. Affected devices should be isolated or patched, and the port should be firewalled.
Azərbaycanca: CVE-2026-61515, Puwell IP kameralarının 2.x-4.x firmware versiyalarında aşkarlanmış autentifikasiyasız əmr inyeksiyası zəifliyidir. Uzaqdan hücumçu TCP 34567 portundakı DebugShell interfeysinə xüsusi JSON yükü göndərərək cihazda ixtiyari OS əmrləri icra edə bilər. Təsirlənən cihazları şəbəkədən təcrid etmək, portu bağlamaq və ya firmware yeniləməsini tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-78
FAQ2
Which Puwell IP camera firmware versions are affected by CVE-2026-61515?
Firmware versions 2.x through 4.x are affected.
How can an attacker exploit CVE-2026-61515 to execute commands on the device?
By sending a crafted JSON payload to the DebugShell interface on TCP port 34567, allowing unauthenticated arbitrary OS command execution.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.