AVer PTC cameras vulnerable to unauthenticated RCE
CVE-2026-40624, an improper input validation flaw in AVer PTC cameras, allows remote unauthenticated attackers to execute arbitrary code via crafted web requests; firmware fix available.
CISA has published an advisory for CVE-2026-40624, a critical vulnerability affecting multiple AVer PTC camera models including PTC500S, PTC115, PTC500+, and PTC115+. The flaw stems from improper input validation that permits a remote, unauthenticated attacker to achieve arbitrary code execution through a specially crafted web request. All versions of the affected camera models are vulnerable.
The affected cameras are deployed worldwide across critical infrastructure sectors including government facilities, commercial facilities, and healthcare. AVer, headquartered in Taiwan, has released a firmware update to remediate the vulnerability. No active exploitation has been reported to CISA at this time.
CISA recommends standard defensive measures including minimizing network exposure, isolating control system networks from business networks, and implementing VPN access where remote connectivity is required. Organizations using these cameras should prioritize patching given the unauthenticated remote code execution risk.
Mentioned in this report
Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-169-01
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free