⚠️ 新漏洞:Puwell 摄像头双重零日,PoC 已公开
安恒信息上周披露,Puwell Technology 旗下 IP 摄像头固件 2.x~4.x 版本存在两个 CVSS 9.8 分的严重漏洞:
CVE-2026-61514:TCP 23456 端口 Session 字段未验证身份,攻击者无需凭据即可登录、操控云台、获取音视频流
CVE-2026-61515:TCP 34567 端口 DebugShell 接口未过滤 JSON 输入,可以 root 权限执行任意命令,设备彻底沦陷
目前 PoC 已公开,厂商补丁尚未发布,全球大量公网暴露的 Puwell 摄像头随时可被接管。
⚠️ New vulnerability: Puwell camera double zero day, PoC has been made public
Anheng Information disclosed last week that Puwell Technology's IP camera firmware versions 2. x to 4. x have two serious vulnerabilities with a CVSS score of 9.8:
CVE-226-61514: TCP 23456 port Session field unverified, attackers can log in, manipulate gimbal, and obtain audio and video streams without credentials
CVE-226-61515: TCP 34567 port Debug Shell interface unfiltered JSON input, can execute arbitrary commands with root privileges, device completely compromised
At present, the PoC has been made public, and the manufacturer's patch has not yet been released. A large number of Puwell cameras exposed on the global public network can be taken over at any time.