CVE-2025-35451
Last modified
CVE-2025-35451 is a critical-severity vulnerability rated 9.3/10 on the CVSS scale. PTZOptics and possibly other ValueHD-based pan-tilt-zoom cameras use hard-coded, default administrative credentials. The passwords can readily be cracked. EPSS estimates a 0.72% chance of exploitation in the next 30 days.
Description
PTZOptics and possibly other ValueHD-based pan-tilt-zoom cameras use hard-coded, default administrative credentials. The passwords can readily be cracked. Many cameras have SSH or telnet listening on all interfaces. The passwords cannot be changed by the user, nor can the SSH or telnet service be disabled by the user.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ptzoptics | Pt12x-Sdi-Xx-G2 Firmware | <= 6.3.34 |
| Ptzoptics | Pt12x-Ndi-Xx Firmware | <= 6.3.34 |
| Ptzoptics | Pt12x-Usb-Xx-G2 Firmware | <= 6.2.81 |
| Ptzoptics | Pt20x-Sdi-Xx-G2 Firmware | <= 6.3.20 |
| Ptzoptics | Pt20x-Ndi-Xx Firmware | <= 6.3.20 |
| Ptzoptics | Pt20x-Usb-Xx-G2 Firmware | <= 6.2.73 |
| Ptzoptics | Pt30x-Sdi-Xx-G2 Firmware | <= 6.3.30 |
| Ptzoptics | Pt30x-Ndi-Xx Firmware | <= 6.3.30 |
| Ptzoptics | Pt12x-Zcam Firmware | <= 7.2.76 |
| Ptzoptics | Pt20x-Zcam Firmware | <= 7.2.82 |
| Ptzoptics | Ptvl-Zcam Firmware | <= 7.2.79 |
| Ptzoptics | Pteptz-Zcam-G2 Firmware | <= 8.1.81 |
| Ptzoptics | Pteptz-Ndi-Zcam-G2 Firmware | <= 8.1.81 |
| Ptzoptics | Vl Fixed Camera Firmware | <= 7.2.94 |
| Ptzoptics | Ndi Fixed Camera Firmware | <= 7.2.94 |
| Multicam-Systems | Mcamii Ptz Firmware | All versions |
| Smtav | Ba30s Firmware | All versions |
| Smtav | Ba20s Firmware | All versions |
| Smtav | Bv20s Firmware | All versions |
| Smtav | Bx30s Firmware | All versions |
| Smtav | Bx20n Firmware | All versions |
| Smtav | Bx20uhd-N Firmware | All versions |
| Smtav | Bx20uhd Firmware | All versions |
| Smtav | Ba30-N Firmware | All versions |
| Smtav | Ba20-N Firmware | All versions |
| Smtav | Ba12-N Firmware | All versions |
| Smtav | Hd17h-N Firmware | All versions |
| Smtav | Bx20s-Sh Firmware | All versions |
| Smtav | Hd17h Firmware | All versions |
| Smtav | Bv30s Firmware | All versions |
| Smtav | Ba12s Firmware | All versions |
| Valuehd | Vx90 Firmware | All versions |
| Valuehd | Vx720l Firmware | All versions |
| Valuehd | Vx752ag Firmware | All versions |
| Valuehd | Vx752a Firmware | All versions |
| Valuehd | Vx751ba Firmware | All versions |
| Valuehd | Vx630al Firmware | All versions |
| Valuehd | Vx61asl Firmware | All versions |
| Valuehd | Vx61basl Firmware | All versions |
| Valuehd | Vx60asl Firmware | All versions |
| Valuehd | Vx61al Firmware | All versions |
| Valuehd | Vx60al Firmware | All versions |
| Valuehd | Vx701ra Firmware | All versions |
| Valuehd | Vx701ta Firmware | All versions |
| Valuehd | Vx800i2 Firmware | All versions |
| Valuehd | V61w Firmware | All versions |
| Valuehd | V63xl Firmware | All versions |
| Valuehd | V60xl Firmware | All versions |
| Valuehd | Vx70uvs Firmware | All versions |
| Valuehd | Vx71uvs Firmware | All versions |
Showing 50 of 51 affected configurations. See NVD for the full list.
References
- https://www.cisa.gov/news-events/ics-advisories/icsa-25-162-10Third Party Advisory, US Government Resource
- https://www.cve.org/CVERecord?id=CVE-2025-35451Third Party Advisory
- https://www.labs.greynoise.io/grimoire/2024-10-31-sift-0-day-rce/Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-35451?
How severe is CVE-2025-35451?
How do I fix CVE-2025-35451?
Are you affected by CVE-2025-35451?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
