CVE-2025-35451
critical · 9.3PTZOptics and possibly other ValueHD-based pan-tilt-zoom cameras use hard-coded, default administrative credentials. The passwords can readily be cracked. Many cameras have SSH or telnet listening on all interfaces. The passwords cannot be changed by the user, nor can the SSH or telnet service be disabled by the user.
9.3
CVSS
0.8%
EPSS (exploit prob.)
54th
EPSS percentile
2025-09-05
Published
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weaknesses
CWE-798
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| ptzoptics | pt12x-sdi-xx-g2_firmware | <= 6.3.34 |
| ptzoptics | pt12x-sdi-xx-g2 | all versions |
| ptzoptics | pt12x-ndi-xx_firmware | <= 6.3.34 |
| ptzoptics | pt12x-ndi-xx | all versions |
| ptzoptics | pt12x-usb-xx-g2_firmware | <= 6.2.81 |
| ptzoptics | pt12x-usb-xx-g2 | all versions |
| ptzoptics | pt20x-sdi-xx-g2_firmware | <= 6.3.20 |
| ptzoptics | pt20x-sdi-xx-g2 | all versions |
| ptzoptics | pt20x-ndi-xx_firmware | <= 6.3.20 |
| ptzoptics | pt20x-ndi-xx | all versions |
| ptzoptics | pt20x-usb-xx-g2_firmware | <= 6.2.73 |
| ptzoptics | pt20x-usb-xx-g2 | all versions |
| ptzoptics | pt30x-sdi-xx-g2_firmware | <= 6.3.30 |
| ptzoptics | pt30x-sdi-xx-g2 | all versions |
| ptzoptics | pt30x-ndi-xx_firmware | <= 6.3.30 |
| ptzoptics | pt30x-ndi-xx | all versions |
| ptzoptics | pt12x-zcam_firmware | <= 7.2.76 |
| ptzoptics | pt12x-zcam | all versions |
| ptzoptics | pt20x-zcam_firmware | <= 7.2.82 |
| ptzoptics | pt20x-zcam | all versions |
| ptzoptics | ptvl-zcam_firmware | <= 7.2.79 |
| ptzoptics | ptvl-zcam | all versions |
| ptzoptics | pteptz-zcam-g2_firmware | <= 8.1.81 |
| ptzoptics | pteptz-zcam-g2 | all versions |
| ptzoptics | pteptz-ndi-zcam-g2_firmware | <= 8.1.81 |
| ptzoptics | pteptz-ndi-zcam-g2 | all versions |
| ptzoptics | vl_fixed_camera_firmware | <= 7.2.94 |
| ptzoptics | vl_fixed_camera | all versions |
| ptzoptics | ndi_fixed_camera_firmware | <= 7.2.94 |
| ptzoptics | ndi_fixed_camera | all versions |
| multicam-systems | mcamii_ptz_firmware | all versions |
| multicam-systems | mcamii_ptz | all versions |
| smtav | ba30s_firmware | all versions |
| smtav | ba30s | all versions |
| smtav | ba20s_firmware | all versions |
| smtav | ba20s | all versions |
| smtav | bv20s_firmware | all versions |
| smtav | bv20s | all versions |
| smtav | bx30s_firmware | all versions |
| smtav | bx30s | all versions |
Check a specific version with /api/v1/cve/match.
References
- https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2025/icsa-25-162-10.json
- https://www.cisa.gov/news-events/ics-advisories/icsa-25-162-10
- https://www.cve.org/CVERecord?id=CVE-2025-35451
- https://www.greynoise.io/blog/greynoise-intelligence-discovers-zero-day-vulnerabilities-in-live-streaming-cameras-with-the-help-of-ai
- https://www.labs.greynoise.io/grimoire/2024-10-31-sift-0-day-rce/
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2025-35451