---
schema: 1
kind: vulnerability
title: "CVE-2026-40624 — AVer PTC-series conference cameras: unauthenticated RCE via the management web interface"
headline: "CVE-2026-40624 — AVer PTC-series conference cameras: unauthenticated RCE via the management web interface"
summary: "AVer PTC-series conference cameras CVE-2026-40624 (CVSS 9.8) — unauthenticated RCE via the management web interface. CISA ICS advisory ICSA-26-169-01; these PTZ cameras sit in government meeting rooms and legislative chambers, directly on the public-sector attack surface (CISA, 2026-06-18)."
discovered_at: "2026-06-20T05:12:14Z"
event_date: 2026-06-19
run_id: 2026-06-20-4cfd00ef
priority: high
immediate_action: null
tags:
  - vulnerabilities
  - pre-auth
  - rce
  - ot-ics
regions:
  - europe
  - switzerland
  - global
sectors:
  - public-sector
  - education
entities: []
cves:
  - id: CVE-2026-40624
    cvss: "9.8"
    epss: null
    type: rce
    vector: zero-click
    auth: pre-auth
    status:
      - patch-available
sources:
  - url: "https://www.cisa.gov/news-events/ics-advisories/icsa-26-169-01"
    publisher: CISA ICS advisory ICSA-26-169-01
    role: primary
  - url: "https://security-hub.ncsc.admin.ch/#/posts/12720"
    publisher: NCSC-CH Security Hub
    role: corroborating
closed_sources: []
evidence: []
verification: multi-source
sourcing_note: null
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions:
  - "**Isolate and patch AVer PTC-series cameras** (CVE-2026-40624): apply firmware, move cameras to a no-egress VLAN, restrict the management interface to admin hosts."
migrated_from: briefs/2026-06-20.md
---

CVE-2026-40624 (CVSS 3.1 9.8; CISA classes it CWE-552, files or directories accessible to external parties) lets a remote, unauthenticated attacker execute arbitrary code on AVer PTC500S, PTC115, PTC500+ and PTC115+ PTZ cameras by sending a crafted request to the web-based management interface ([CISA ICS advisory ICSA-26-169-01, 2026-06-18](https://www.cisa.gov/news-events/ics-advisories/icsa-26-169-01)). NCSC-CH echoed the advisory the following day and lists exploitation status as unknown ([NCSC-CH, 2026-06-19](https://security-hub.ncsc.admin.ch/#/posts/12720)). These cameras are common in government meeting rooms, lecture halls and legislative-chamber hybrid-meeting setups — placed adjacent to meeting infrastructure on frequently flat networks, they offer device takeover plus a lateral-movement foothold. AVer has shipped firmware fixes; interim mitigation is to put cameras on an isolated VLAN with no internet egress and restrict the management interface to trusted admin hosts. Hunt for unexpected HTTP requests to the camera management interface from non-admin subnets and any outbound connections initiated by camera IP ranges (cameras should never initiate arbitrary egress).
