ZeroHour

CVE-2025-35451

PoC
CVSS 4.0
9.3 critical
EPSS
<1%p54
Published
()
Modified
Description

PTZOptics and possibly other ValueHD-based pan-tilt-zoom cameras use hard-coded, default administrative credentials. The passwords can readily be cracked. Many cameras have SSH or telnet listening on all interfaces. The passwords cannot be changed by the user, nor can the SSH or telnet service be disabled by the user.

Vendors
ptzopticsmulticam-systemssmtavvaluehd
Products
pt12x-sdi-xx-g2 firmware, pt12x-ndi-xx firmware, pt12x-usb-xx-g2 firmware, pt20x-sdi-xx-g2 firmware, pt20x-ndi-xx firmware, pt20x-usb-xx-g2 firmware, pt30x-sdi-xx-g2 firmware, pt30x-ndi-xx firmware, pt12x-zcam firmware, pt20x-zcam firmware, ptvl-zcam firmware, pteptz-zcam-g2 firmware
Weakness
CWE-798
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.