# Critical Remote Code Execution Flaw Exposes Thousands of AVer PTC Cameras Worldwide


## The Threat


AVer's PTC series presentation cameras—widely deployed across government facilities, hospitals, and corporate meeting rooms—contain a critical vulnerability that allows attackers to seize complete control of the devices without authentication or user interaction. CVE-2026-40624 stems from improper input validation in the camera's web interface, permitting remote attackers to inject arbitrary code and execute it with full system privileges.


Presentation cameras are ubiquitous in enterprise environments. They sit in conference rooms, lecture halls, and control centers, often connected directly to corporate networks or—worse—the internet. They're frequently overlooked in security audits because they're perceived as "just cameras," yet they provide attackers a foothold into building networks, can be used to exfiltrate data during sensitive meetings, and can serve as pivots into more critical systems. This vulnerability transforms them from passive viewing devices into active attack vectors.


The attack requires no authentication, no user interaction, and can be delivered over the network from anywhere with routing access to the target camera. An attacker can craft a single malicious HTTP request and instantly gain code execution, making exploitation trivial to automate and scale. CISA has flagged this as affecting critical infrastructure sectors including government, healthcare, and commercial facilities worldwide.


## Severity and Impact


| Attribute | Details |

|---|---|

| CVE | CVE-2026-40624 |

| CVSS v3.1 Score | 9.8 (Critical) |

| CVSS v4.0 Score | 9.3 (Critical) |

| Vector (v3.1) | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |

| Vector (v4.0) | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |

| Attack Vector | Network |

| Attack Complexity | Low |

| Authentication Required | None |

| User Interaction | None |

| Scope | Unchanged |

| Confidentiality Impact | High |

| Integrity Impact | High |

| Availability Impact | High |

| CWE | CWE-552 (Files or Directories Accessible to External Parties) |


The vulnerability receives maximum severity scores under both CVSS 3.1 and 4.0 metrics, reflecting the combination of network accessibility, zero authentication requirements, and the attacker's ability to achieve full system compromise in a single request.


## Affected Products


The following AVer PTC camera models are vulnerable in all firmware versions:


  • AVer PTC500S (all versions)
  • AVer PTC115 (all versions)
  • AVer PTC500+ (all versions)
  • AVer PTC115+ (all versions)

  • Organizations running any of these four models should assume their cameras are exploitable unless patched. AVer has not released a statement limiting vulnerability to specific firmware versions or hardware revisions.


    ## Mitigations


    Immediate Actions:


    1. Firmware Update — AVer has released a patch. Download and deploy the latest firmware immediately from the AVer support portal at https://presentation.aver.com/. This is the primary remediation and should be your first priority.


    2. Network Isolation — If firmware updates cannot be deployed immediately, implement network controls:

    - Move PTC cameras behind a firewall and restrict inbound access to authorized subnets only

    - Block internet-facing access to the cameras' web interfaces (typically port 80/443)

    - Use network segmentation to isolate cameras from sensitive systems and user data networks

    - Disable UPnP and any auto-discovery mechanisms that could expose cameras to the wider network


    3. Access Controls — If cameras must remain internet-accessible, implement:

    - IP whitelisting at the firewall or reverse proxy layer

    - VPN requirement for remote access (though recognize VPNs themselves may have vulnerabilities)

    - Web application firewall (WAF) rules to detect and block suspicious HTTP requests targeting the camera's input validation endpoints


    4. Network Monitoring — Enable logging and alerting on:

    - Unexpected HTTP requests to camera IP addresses

    - Access to administrative endpoints or firmware upload functions

    - Unusual outbound traffic from cameras

    - Failed login attempts (if authentication is configured)


    5. Asset Inventory — Conduct a thorough scan of your network to identify all AVer PTC cameras, including those in conference rooms, training facilities, and remote offices. Many organizations lose visibility into networked devices in distributed locations.


    Recommended Practices (per CISA):


  • Assume all control system devices are potential entry points and minimize their network exposure
  • Perform impact analysis before deploying mitigations to avoid disrupting critical operations
  • Follow CISA's Defense-in-Depth strategies for ICS security (available at cisa.gov/ics)

  • ## References


  • [CISA Alert (Original Advisory)](https://www.cisa.gov/)
  • [AVer Firmware Downloads](https://presentation.aver.com/DownloadFile.aspx?n=6617|1C01A887-7CDC-4C96-AD9A-11D53DE1AD71&t=ServiceDownload)
  • [CVE-2026-40624 Details](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-40624)
  • [CWE-552: Files or Directories Accessible to External Parties](https://cwe.mitre.org/data/definitions/552.html)

  • ---


    ## HackWire Analysis


    This vulnerability highlights a painful pattern in IoT and enterprise hardware security: devices are shipped with functionality first and security hardening second. Presentation cameras are not novel targets—they've been exploitable in past incidents, yet AVer allowed input validation gaps to persist across every firmware version of four popular models deployed in thousands of critical facilities.


    The risk extends beyond the camera itself. A compromised PTC device gives attackers a legitimate foothold inside a healthcare network, government office, or corporate facility. From there, they can conduct reconnaissance, capture credentials and intellectual property shared during meetings, or pivot laterally into more valuable systems. For healthcare facilities under HIPAA, this creates potential breach notification obligations. For government agencies, it's a counterintelligence nightmare.


    The timeline matters too. CISA is publicizing this now, which means patches should already be available and deployments should begin immediately. However, in many organizations, presentation cameras are managed by facilities or AV teams, not IT security. They often lack formal patch management processes and may not receive updates for months—or ever. The firmware update, while available, requires physical or administrative access to perform; in distributed environments with hundreds of conference rooms, deployment will take time.


    The CWE classification (CWE-552: Files or Directories Accessible to External Parties) also suggests the vulnerability may involve exposure of sensitive configuration files or backup data, not just the input validation flaw itself. If that's the case, even patching won't delete what's already been exfiltrated. Organizations should assume exposure and treat camera credentials as compromised.


    Defenders should treat this as a drill for broader supply chain risk. Consumer-facing device manufacturers (cameras, displays, speakers) frequently underinvest in security and patch management. Identifying and isolating these devices before attackers do is table stakes for modern security programs.


    — HackWire Editorial


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)