CVE-2026-26461

Medium severity, CVSS 6.5. EPSS: 1.5% chance of exploitation in the next 30 days.

A Command Injection vulnerability in the web management interface in Aver PTC320UV2 0.1.0000.65 allows an unauthenticated attacker to execute arbitrary commands via a crafted web request.

Published 2026-05-01. Last modified 2026-06-17.