CVE-2025-35451
Last modified
CVE-2025-35451 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. PTZOptics and possibly other ValueHD-based pan-tilt-zoom cameras use hard-coded, default administrative credentials. The passwords can readily be cracked. EPSS estimates a 0.72% chance of exploitation in the next 30 days.
Description
PTZOptics and possibly other ValueHD-based pan-tilt-zoom cameras use hard-coded, default administrative credentials. The passwords can readily be cracked. Many cameras have SSH or telnet listening on all interfaces. The passwords cannot be changed by the user, nor can the SSH or telnet service be disabled by the user.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ptzoptics | Pt12x-Sdi-Xx-G2 Firmware | <= 6.3.34 |
| Ptzoptics | Pt12x-Ndi-Xx Firmware | <= 6.3.34 |
| Ptzoptics | Pt12x-Usb-Xx-G2 Firmware | <= 6.2.81 |
| Ptzoptics | Pt20x-Sdi-Xx-G2 Firmware | <= 6.3.20 |
| Ptzoptics | Pt20x-Ndi-Xx Firmware | <= 6.3.20 |
| Ptzoptics | Pt20x-Usb-Xx-G2 Firmware | <= 6.2.73 |
| Ptzoptics | Pt30x-Sdi-Xx-G2 Firmware | <= 6.3.30 |
| Ptzoptics | Pt30x-Ndi-Xx Firmware | <= 6.3.30 |
| Ptzoptics | Pt12x-Zcam Firmware | <= 7.2.76 |
| Ptzoptics | Pt20x-Zcam Firmware | <= 7.2.82 |
| Ptzoptics | Ptvl-Zcam Firmware | <= 7.2.79 |
| Ptzoptics | Pteptz-Zcam-G2 Firmware | <= 8.1.81 |
| Ptzoptics | Pteptz-Ndi-Zcam-G2 Firmware | <= 8.1.81 |
| Ptzoptics | Vl Fixed Camera Firmware | <= 7.2.94 |
| Ptzoptics | Ndi Fixed Camera Firmware | <= 7.2.94 |
| Multicam-Systems | Mcamii Ptz Firmware | All versions |
| Smtav | Ba30s Firmware | All versions |
| Smtav | Ba20s Firmware | All versions |
| Smtav | Bv20s Firmware | All versions |
| Smtav | Bx30s Firmware | All versions |
| Smtav | Bx20n Firmware | All versions |
| Smtav | Bx20uhd-N Firmware | All versions |
| Smtav | Bx20uhd Firmware | All versions |
| Smtav | Ba30-N Firmware | All versions |
| Smtav | Ba20-N Firmware | All versions |
| Smtav | Ba12-N Firmware | All versions |
| Smtav | Hd17h-N Firmware | All versions |
| Smtav | Bx20s-Sh Firmware | All versions |
| Smtav | Hd17h Firmware | All versions |
| Smtav | Bv30s Firmware | All versions |
| Smtav | Ba12s Firmware | All versions |
| Valuehd | Vx90 Firmware | All versions |
| Valuehd | Vx720l Firmware | All versions |
| Valuehd | Vx752ag Firmware | All versions |
| Valuehd | Vx752a Firmware | All versions |
| Valuehd | Vx751ba Firmware | All versions |
| Valuehd | Vx630al Firmware | All versions |
| Valuehd | Vx61asl Firmware | All versions |
| Valuehd | Vx61basl Firmware | All versions |
| Valuehd | Vx60asl Firmware | All versions |
| Valuehd | Vx61al Firmware | All versions |
| Valuehd | Vx60al Firmware | All versions |
| Valuehd | Vx701ra Firmware | All versions |
| Valuehd | Vx701ta Firmware | All versions |
| Valuehd | Vx800i2 Firmware | All versions |
| Valuehd | V61w Firmware | All versions |
| Valuehd | V63xl Firmware | All versions |
| Valuehd | V60xl Firmware | All versions |
| Valuehd | Vx70uvs Firmware | All versions |
| Valuehd | Vx71uvs Firmware | All versions |
Showing 50 of 51 affected configurations. See NVD for the full list.
References
- https://www.cisa.gov/news-events/ics-advisories/icsa-25-162-10Third Party Advisory, US Government Resource
- https://www.cve.org/CVERecord?id=CVE-2025-35451Third Party Advisory
- https://www.labs.greynoise.io/grimoire/2024-10-31-sift-0-day-rce/Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-35451?
How severe is CVE-2025-35451?
How do I fix CVE-2025-35451?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-35433CISA Thorium does not properly invalidate previously used to…8.8
- CVE-2025-35434CISA Thorium does not validate TLS certificates when connect…9.8
- CVE-2025-35435CISA Thorium accepts a stream split size of zero then divide…5.3
- CVE-2025-35436CISA Thorium uses '.unwrap()' to handle errors related to ac…7.5
- CVE-2025-3544A vulnerability was found in H3C Magic NX15, Magic NX30 Pro,…8.6
- CVE-2025-3545A vulnerability was found in H3C Magic NX15, Magic NX30 Pro,…8.6
- CVE-2025-35452PTZOptics and possibly other ValueHD-based pan-tilt-zoom cam…9.8
- CVE-2025-3546A vulnerability was found in H3C Magic NX15, Magic NX30 Pro,…8.6
- CVE-2025-3547A vulnerability classified as critical was found in frdel Ag…6.3
- CVE-2025-35471conda-forge openssl-feedstock before 066e83c (2024-05-20), o…7.8
- CVE-2025-3548A vulnerability, which was classified as critical, has been …3.3
- CVE-2025-3549A vulnerability, which was classified as critical, was found…3.3
Are you affected by CVE-2025-35451?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
