9.8
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
PTZOptics and possibly other ValueHD-based pan-tilt-zoom cameras use default, shared credentials for the administrative web interface.
Basic Information
ID
CVE-2025-35452
Source
cisa-cg
Published
Sep 5, 2025 at 17:49
Modified
Sep 5, 2025 at 18:59
Affected Product
Vendor
PTZOptics
Product
PT12X-SE-xx-G3
Affected Versions
PTZOptics PT12X-SE-xx-G3 0
PTZOptics PT12X-LINK-4K-xx 0
PTZOptics PT20X-SE-xx-G3 0
PTZOptics PT20X-LINK-4K-xx 0
PTZOptics PT30X-SE-xx-G3 0
PTZOptics PT30X-LINK-4K-xx 0
PTZOptics PT-STUDIOPRO 0
PTZOptics PT12X-STUDIO-4K-xx-G3 0
PTZOptics PT20X-STUDIO-4K-xx-G3 0
PTZOptics PT12X-SDI/NDI-xx 0
PTZOptics PT12X-USB-xx 0
PTZOptics PT20X-SDI/NDI-xx 0
SMTAV Pan-Tilt-Zoom Cameras *
PTZOptics PT30X-SDI/NDI-xx 0
multiCAM Systems Pan-Tilt-Zoom Cameras *
PTZOptics VL Fixed Camera/NDI Fixed Camera 0
PTZOptics 12x Fixed Camera/NDI Fixed Camera 0
PTZOptics 20x Fixed Camera/NDI Fixed Camera 0
PTZOptics EPTZ Fixed Camera/NDI Fixed Camera 0
PTZOptics HC-EPTZ-NDI 0
PTZOptics PT12X-4K-xx-G3 0
PTZOptics PT20X-4K-xx-G3 0
PTZOptics PT30X-4K-xx-G3 0
PTZOptics PT20X-USB-xx 0
ValueHD Pan-Tilt-Zoom Cameras *
PTZOptics PT12X-LINK-4K-xx 0
PTZOptics PT20X-SE-xx-G3 0
PTZOptics PT20X-LINK-4K-xx 0
PTZOptics PT30X-SE-xx-G3 0
PTZOptics PT30X-LINK-4K-xx 0
PTZOptics PT-STUDIOPRO 0
PTZOptics PT12X-STUDIO-4K-xx-G3 0
PTZOptics PT20X-STUDIO-4K-xx-G3 0
PTZOptics PT12X-SDI/NDI-xx 0
PTZOptics PT12X-USB-xx 0
PTZOptics PT20X-SDI/NDI-xx 0
SMTAV Pan-Tilt-Zoom Cameras *
PTZOptics PT30X-SDI/NDI-xx 0
multiCAM Systems Pan-Tilt-Zoom Cameras *
PTZOptics VL Fixed Camera/NDI Fixed Camera 0
PTZOptics 12x Fixed Camera/NDI Fixed Camera 0
PTZOptics 20x Fixed Camera/NDI Fixed Camera 0
PTZOptics EPTZ Fixed Camera/NDI Fixed Camera 0
PTZOptics HC-EPTZ-NDI 0
PTZOptics PT12X-4K-xx-G3 0
PTZOptics PT20X-4K-xx-G3 0
PTZOptics PT30X-4K-xx-G3 0
PTZOptics PT20X-USB-xx 0
ValueHD Pan-Tilt-Zoom Cameras *
CWE Classification
References
- www.cisa.gov /news-events/ics-advisories/icsa-25-162-10
- github.com /cisagov/CSAF/blob/develop/csaf_files/OT/white/2025/icsa-25-162-10.json
- www.cve.org /CVERecord
- www.labs.greynoise.io /grimoire/2024-10-31-sift-0-day-rce/
- www.greynoise.io /blog/greynoise-intelligence-discovers-zero-day-vulnerabilities-in-live-streaming-cameras-with-the-help-of-ai