ptzoptics CVE Vulnerabilities & CVE List (4)

Products (CPE): — CVEs: 4

ptzoptics vulnerability overview

Aggregates CVE and security vulnerability intelligence across all ptzoptics-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Historical issues mainly involve vendor risk command injection and related problems; some flaws may lead to vendor impact file overwrite, affecting vendor surface production workloads scenarios.

Vulnerability distribution trend (last 24 months)

Showing 14 of 4 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2025-35452 PTZOptics and possibly other ValueHD-based pan-tilt-zoom cameras use default, shared credentials for the administrative web interface. 9119a7d8-5eab-497f-8521-727c672e3725 9.2 0.79% 2025-09-05 2026-06-17
CVE-2025-35451 PTZOptics and possibly other ValueHD-based pan-tilt-zoom cameras use hard-coded, default administrative credentials. The passwords can readily be cracked. Many cameras have SSH or telnet listening on all interfaces. The passwords cannot be changed by the user, nor can the SSH or telnet service be disabled by the user. 9119a7d8-5eab-497f-8521-727c672e3725 9.3 0.72% 2025-09-05 2026-06-17
CVE-2024-8957 KEV PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an OS command injection issue. The camera does not sufficiently validate the ntp_addr configuration value which may lead to arbitrary command execution when ntp_client is started. When chained with CVE-2024-8956, a remote and unauthenticated attacker can execute arbitrary OS commands on affected devices. [email protected] 7.2 81.97% 2024-09-17 2026-06-17
CVE-2024-8956 KEV PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an insufficient authentication issue. The camera does not properly enforce authentication to /cgi-bin/param.cgi when requests are sent without an HTTP Authorization header. The result is a remote and unauthenticated attacker can leak sensitive data such as usernames, password hashes, and configurations details. Additionally, the attacker can update individual configuration values or overwrite the whole file. [email protected] 9.1 60.88% 2024-09-17 2026-06-17
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence