CVE-2025-35452

CRITICALCVSS 9.2/10EPSS 0.79%

Last modified

CVE-2025-35452 is a critical-severity vulnerability rated 9.2/10 on the CVSS scale. PTZOptics and possibly other ValueHD-based pan-tilt-zoom cameras use default, shared credentials for the administrative web interface.. EPSS estimates a 0.79% chance of exploitation in the next 30 days.

Description

PTZOptics and possibly other ValueHD-based pan-tilt-zoom cameras use default, shared credentials for the administrative web interface.

Metrics

CVSS 3.1
9.8/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS 4.0
9.2/10

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

EPSS Probability
0.79%

51.7th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
PtzopticsPt12x-Sdi-Xx-G2 FirmwareAll versions
PtzopticsPt12x-Ndi-Xx FirmwareAll versions
PtzopticsPt12x-Usb-Xx-G2 FirmwareAll versions
PtzopticsPt20x-Sdi-Xx-G2 FirmwareAll versions
PtzopticsT20x-Ndi-Xx FirmwareAll versions
PtzopticsPt20x-Usb-Xx-G2 FirmwareAll versions
PtzopticsPt30x-Sdi-Xx-G2 FirmwareAll versions
PtzopticsPt30x-Ndi-Xx FirmwareAll versions
PtzopticsPt12x-Zcam FirmwareAll versions
PtzopticsPt20x-Zcam FirmwareAll versions
PtzopticsPtvl-Zcam FirmwareAll versions
PtzopticsPteptz-Zcam-G2 FirmwareAll versions
PtzopticsPteptz-Ndi-Zcam-G2All versions
PtzopticsPt12x-4k-Xx-G3 Firmware<= 0.0.58
PtzopticsPt20x-4k-Xx-G3 Firmware<= 0.0.85
PtzopticsPt30x-4k-Xx-G3 Firmware<= 2.0.64
PtzopticsPt12x-Link-4k-Xx Firmware<= 0.0.63
PtzopticsPt20x-Link-4k-Xx Firmware<= 0.0.89
PtzopticsPt30x-Link-4k-Xx Firmware<= 2.0.71
PtzopticsPt12x-Se-Xx-G3 Firmware<= 9.1.43
PtzopticsPt20x-Se-Xx-G3 Firmware<= 9.1.32
PtzopticsPt30x-Se-Xx-G3 Firmware<= 9.1.33
PtzopticsPt-Studiopro Firmware<= 9.0.41
PtzopticsVl Fixed Camera Firmware<= 7.2.94
PtzopticsNdi Fixed Camera Firmware<= 7.2.94
Multicam-SystemsMcamii Ptz FirmwareAll versions
SmtavBa30s FirmwareAll versions
SmtavBa20s FirmwareAll versions
SmtavBv20s FirmwareAll versions
SmtavBx30s FirmwareAll versions
SmtavBx20n FirmwareAll versions
SmtavBx20uhd-N FirmwareAll versions
SmtavBx20uhd FirmwareAll versions
SmtavBa30-N FirmwareAll versions
SmtavBa20-N FirmwareAll versions
SmtavBa12-N FirmwareAll versions
SmtavHd17h-N FirmwareAll versions
SmtavBx20s-Sh FirmwareAll versions
SmtavHd17h FirmwareAll versions
SmtavBv30s FirmwareAll versions
SmtavBa12s FirmwareAll versions
ValuehdVx90 FirmwareAll versions
ValuehdVx720l FirmwareAll versions
ValuehdVx752ag FirmwareAll versions
ValuehdVx752a FirmwareAll versions
ValuehdVx751ba FirmwareAll versions
ValuehdVx630al FirmwareAll versions
ValuehdVx61asl FirmwareAll versions
ValuehdVx61basl FirmwareAll versions
ValuehdVx60asl FirmwareAll versions

Showing 50 of 61 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Analyzed

Frequently Asked Questions

What is CVE-2025-35452?
PTZOptics and possibly other ValueHD-based pan-tilt-zoom cameras use default, shared credentials for the administrative web interface.
How severe is CVE-2025-35452?
CVE-2025-35452 has a CVSS score of 9.2/10 (CRITICAL severity). The EPSS model estimates a 0.79% probability of exploitation in the next 30 days.
How do I fix CVE-2025-35452?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2025-35452?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST