CVE-2026-40624: Aver PTC115

Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.

Improper input validation in AVer PTC500S, PTC115, PTC500+, and PTC115+ cameras may allow a remote, unauthenticated attacker to achieve arbitrary code execution via a specially crafted web request.

Affected products

  • Aver PTC115: any version
  • Aver PTC115+: any version
  • Aver PTC500+: any version
  • Aver PTC500S: any version

Published 2026-06-19. Last modified 2026-06-22.