Vulnerabilities
4 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-35451 +1 in the same advisory: …35452 | PTZOptics and possibly other ValueHD-based pan-tilt-zoom cameras use hard-coded, default administrative credentials. PTZOptics and possibly other ValueHD-based pan-tilt-zoom cameras use hard-coded, default administrative credentials. The passwords can readily be cracked. Many cameras have SSH or telnet listening on all interfaces. The passwords cannot be changed by the user, nor can the SSH or telnet service be disabled by the user. NVD description · AI analysis pending | 9.3 group max | <1% | PoC |
| — | |
| CVE-2024-8956 +1 in the same advisory: …8957 | Authentication Bypass in PTZOptics PT30X-SDI/NDI Cameras Leaks Credentials PTZOptics PT30X-SDI and PT30X-NDI-XX-G2 cameras fail to enforce authentication on the /cgi-bin/param.cgi endpoint when HTTP requests omit the Authorization header. By sending crafted requests without that header, a remote unauthenticated attacker can read sensitive data including usernames, password hashes, and configuration details, and can modify individual configuration values or overwrite the entire configuration file. Any PTZOptics PT30X-SDI or PT30X-NDI-XX-G2 camera running firmware prior to 6.3.40 is affected, particularly units reachable from untrusted networks. The flaw is confirmed to be exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-11-04, and a public PoC reference from GreyNoise (2024-10-31) describes it as a zero-day being exploited. With an EPSS of 61.3% (99th percentile), widespread opportunistic exploitation is expected in the coming weeks. Do: Upgrade affected PT30X-SDI and PT30X-NDI-XX-G2 cameras to firmware 6.3.40 or later as required by CISA's KEV listing. Until patched, restrict HTTP access to the cameras with firewall/ACL rules and avoid exposing the web interface to the internet. Check camera configuration for unexpected changes, and rotate camera credentials since usernames and password hashes may have been disclosed. | 9.1 group max | 61% | KEV PoC |
| nichelikely low thousands of internet-exposed units, with an unknown total installed base |