CVE-2025-35451 - CVE House
Back to Database
Status published Critical CVE-2025-35451

Pan-Tilt-Zoom cameras hard-coded default passwords with SSH and telnet enabled

Vulnerability Description

PTZOptics and possibly other ValueHD-based pan-tilt-zoom cameras use hard-coded, default administrative credentials. The passwords can readily be cracked. Many cameras have SSH or telnet listening on all interfaces. The passwords cannot be changed by the user, nor can the SSH or telnet service be disabled by the user.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-35451

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

PT12X-SE-xx-G3, PT12X-LINK-4K-xx, PT20X-SE-xx-G3, PT20X-LINK-4K-xx, PT-STUDIOPRO, PT30X-SE-xx-G3, PT30X-LINK-4K-xx, PT12X-STUDIO-4K-xx-G3, PT20X-STUDIO-4K-xx-G3, PT12X-SDI/NDI-xx, PT12X-USB-xx, PT20X-SDI/NDI-xx, Pan-Tilt-Zoom Cameras, PT30X-SDI/NDI-xx, VL Fixed Camera/NDI Fixed Camera, 12x Fixed Camera/NDI Fixed Camera, 20x Fixed Camera/NDI Fixed Camera, EPTZ Fixed Camera/NDI Fixed Camera, HC-EPTZ-NDI, PT12X-4K-xx-G3, PT20X-4K-xx-G3, PT20X-USB-xx, PT30X-4K-xx-G3
Vulnerable Versions:
0, 9.1.43, 0.0.63, 9.1.32, 0.0.89, 9.0.41, 9.1.33, 2.0.71, 8.1.90, 6.3.70, 6.2.88, 6.3.27, *, 6.3.43, 7.2.94, 7.2.85, 8.1.89, 8.2.14, 0.0.58, 0.0.85, 6.2.81, 2.0.64

Timeline

Official Publish: September 5th, 2025
Last Modified: September 8th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)