External risk intelligence

Puwell IP Camera Authentication Bypass via TCP Port 23456

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-61514

The vulnerability affects IP cameras, which are frequently deployed with internet-facing network configurations to facilitate remote monitoring. The device listens on a specific TCP port for control traffic, and because these devices are commonly exposed to the internet for remote access, this surface is considered likely to be reachable in real-world deployments.

Missing Authentication

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability in Puwell IP camera firmware allows unauthenticated access to device functions through a network port. This could enable unauthorized individuals to view live video streams, control camera movements, and activate audio features, among other actions. The primary concern is confirming if this type of device is in use and if it is accessible via the network.

  • Unauthenticated attackers can access camera functions remotely.
  • It affects remote monitoring and potentially sensitive environments.
  • Confirm relevance and exposure of affected devices.

Attack Path

How an attacker could exploit the issue

Attackers can reach vulnerable Puwell IP cameras over the network and bypass authentication to control device functions. The attacker's journey begins by sending specially crafted packets to TCP port 23456. This unauthenticated access allows them to interact with the camera's proprietary control protocol, leading to unauthorized control over video streams, camera movement, audio, and device restarts.

  • Exposed network service.
  • Unauthenticated control protocol access.
  • Unauthorized device control and monitoring.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability in Puwell IP camera firmware could allow unauthenticated attackers to bypass access controls. When the device is reachable over TCP port 23456, attackers may exploit a flaw in the proprietary control protocol to access live video streams, control camera movement, activate audio features, and remotely restart the device.

  • Live video streams and device control.
  • Sending protocol-conforming packets.
  • Unauthorized access and remote restart.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Puwell IP camera vulnerability likely impacts device owners and infrastructure teams responsible for maintaining network-connected security devices. The first practical step is to identify all deployed Puwell IP cameras, assess their network exposure and criticality, and then locate the accountable owner for remediation planning.

  • Device owners, platform teams should own.
  • Verify device network exposure and criticality.
  • Plan remediation based on risk and vendor coordination.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Puwell IP camera?

Puwell IP cameras are network-connected video surveillance devices used for security monitoring. They function by capturing, processing, and transmitting video data over IP networks. These units often include motorized controls for pan and tilt functions and audio hardware, allowing users to monitor and manage physical spaces remotely via the manufacturer's firmware.

What does CWE-306 mean for CVE-2026-61514?

CWE-306 refers to a Missing Authentication for Critical Function weakness. In the context of this CVE, it means the camera's firmware fails to verify the identity of a user before granting access to sensitive controls. Instead of requiring a password or token, the device accepts commands directly, allowing anyone who can reach the device to execute restricted operations.

How is this vulnerability triggered?

The vulnerability is triggered when an attacker sends specifically formatted packets to TCP port 23456. This port handles the camera's proprietary control protocol. If the incoming packet contains an unvalidated Session field, the camera processes the request without checking for credentials. Simple network traffic that does not conform to this proprietary protocol structure will not trigger this specific flaw.

Is my device at risk based on Halo Surface Signal?

Halo Surface Signal indicates that the risk is high if your camera is configured to be internet-facing. Because these cameras are frequently exposed to the public internet to enable remote viewing, they are often reachable by outside parties. You should verify if your device is accessible from the network rather than just local, as internet-accessible cameras are the primary targets.

What should I do first if I have Puwell cameras?

Start by identifying all Puwell cameras currently in use within your environment. Once you have a list of these assets, assess their network configuration to determine if they are exposed to the internet. Contact the relevant system owners to coordinate a review of device placement and consult official vendor support channels for guidance on securing or updating these units.

References