ctipilot.ch

AVer PTC500S/PTC115/PTC500+/PTC115+ cameras — unauthenticated RCE via management web interface (CVSS 9.8), CISA ICSA-26-169-01

cve · CVE-2026-40624

Coverage timeline
1
first 2026-06-20 → last 2026-06-21
Peak priority
high
1 high
Sources cited
2
2 hosts
Sections touched
1
trending-vulnerabilities
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
0
no mapped behavior yet

Story timeline

  1. 2026-06-20CVE-2026-40624 — AVer PTC-series conference cameras: unauthenticated RCE via the management web interface
    trending-vulnerabilities

Where this entity is cited

  • trending-vulnerabilities1

Source distribution

  • cisa.gov1 (50%)
  • security-hub.ncsc.admin.ch1 (50%)

explore in graph

Entries about AVer PTC500S/PTC115/PTC500+/PTC115+ cameras — unauthenticated RCE via management web interface (CVSS 9.8), CISA ICSA-26-169-01 (1)

2026-06-20 · view entry permalink →

CVE-2026-40624 — AVer PTC-series conference cameras: unauthenticated RCE via the management web interface

CVE-2026-40624 (CVSS 3.1 9.8; CISA classes it CWE-552, files or directories accessible to external parties) lets a remote, unauthenticated attacker execute arbitrary code on AVer PTC500S, PTC115, PTC500+ and PTC115+ PTZ cameras by sending a crafted request to the web-based management interface (CISA ICS advisory ICSA-26-169-01, 2026-06-18). NCSC-CH echoed the advisory the following day and lists exploitation status as unknown (NCSC-CH, 2026-06-19). These cameras are common in government meeting rooms, lecture halls and legislative-chamber hybrid-meeting setups — placed adjacent to meeting infrastructure on frequently flat networks, they offer device takeover plus a lateral-movement foothold. AVer has shipped firmware fixes; interim mitigation is to put cameras on an isolated VLAN with no internet egress and restrict the management interface to trusted admin hosts. Hunt for unexpected HTTP requests to the camera management interface from non-admin subnets and any outbound connections initiated by camera IP ranges (cameras should never initiate arbitrary egress).

vulnerability20 Jun 05:12Zmulti-sourceOpen finding ↗