CVE-2026-61515PoC

LOWCVSS 9.3 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Puwell IP Camera firmware versions 2.x through 4.x contains an unauthenticated command injection vulnerability that allows remote attackers to execute arbitrary operating system commands by sending a crafted JSON payload to the DebugShell interface exposed on TCP port 34567. Attackers can exploit the lack of authentication and input sanitization in the binary protocol service to pass arbitrary commands directly to the underlying operating system, achieving root-level code execution and complete device compromise.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-912

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Threat summary

  • Public PoC and exploit tooling are both present
  • 1 mentions across 1 observed day

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-12: 1PoC Mentioned / Linked · 2026-08-12: 1Exploit Tool / Code · 2026-08-12: 1Technical Details · 2026-08-12: 108-12
Signal classification1 categories
PoC
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • Daily CyberSecurity@Daily_CyberSec
    PoC

    PoC exploit code is public for CVE-2026-61515, an unauthenticated command injection in Puwell IP Camera firmware. CVSS 9.3. Details inside. #IPCamera #IoT #CVE #CommandInjection #CyberSecurity http://securityonline.info/puwell-ip-camera-vulnerabilities/

    Post summary

    The post announces that a public PoC exploit exists for CVE-2026-61515, a critical unauthenticated command injection vulnerability in Puwell IP Camera firmware (CVSS 9.3), but does not mention active exploitation or any patch.

    02050655
    13.0K followersView on X

Explore more