CISA

AVer PTC cameras

From Cybersecurity and Infrastructure Security Agency ↗

Successful exploitation of this vulnerability could allow arbitrary code execution.

The following versions of AVer PTC cameras are affected:

PTC500S vers:all/* (CVE-2026-40624)

PTC115 vers:all/* (CVE-2026-40624)

PTC500+ vers:all/* (CVE-2026-40624)

PTC115+ vers:all/* (CVE-2026-40624)

Vendor

Equipment

AVer

AVer PTC cameras

Files or Directories Accessible to External Parties

Critical Infrastructure Sectors: Government Services and Facilities, Commercial Facilities, Healthcare and Public Health

Countries/Areas Deployed: Worldwide

Company Headquarters Location: Taiwan

Improper input validation in AVer PTC500S, PTC115, PTC500+, and PTC115+ cameras may allow a remote, unauthenticated attacker to achieve arbitrary code execution via a specially crafted web request.

AVer PTC cameras

MitigationAVer has provided a firmware fix to address this vulnerability; users can find it at t...