# AVer PTC cameras vulnerable to unauthenticated RCE

Published: 2026-06-18 · Severity: high · Sectors: government-national, healthcare
Canonical: https://vorant.io/reports/4956b114-41dc-5f00-a85e-9f020210b9d7/aver-ptc-cameras-vulnerable-to-unauthenticated-rce

> CVE-2026-40624, an improper input validation flaw in AVer PTC cameras, allows remote unauthenticated attackers to execute arbitrary code via crafted web requests; firmware fix available.

CISA has published an advisory for CVE-2026-40624, a critical vulnerability affecting multiple AVer PTC camera models including PTC500S, PTC115, PTC500+, and PTC115+. The flaw stems from improper input validation that permits a remote, unauthenticated attacker to achieve arbitrary code execution through a specially crafted web request. All versions of the affected camera models are vulnerable.

The affected cameras are deployed worldwide across critical infrastructure sectors including government facilities, commercial facilities, and healthcare. AVer, headquartered in Taiwan, has released a firmware update to remediate the vulnerability. No active exploitation has been reported to CISA at this time.

CISA recommends standard defensive measures including minimizing network exposure, isolating control system networks from business networks, and implementing VPN access where remote connectivity is required. Organizations using these cameras should prioritize patching given the unauthenticated remote code execution risk.

## Mentioned in this report

- Vulnerabilities: CVE-2026-40624

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-169-01

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/4956b114-41dc-5f00-a85e-9f020210b9d7/aver-ptc-cameras-vulnerable-to-unauthenticated-rce.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
