Back to Database
Status published
Critical
CVE-2025-35452
Pan-Tilt-Zoom cameras default administrative credentials for web interface
Vulnerability Description
PTZOptics and possibly other ValueHD-based pan-tilt-zoom cameras use default, shared credentials for the administrative web interface.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-35452
Credits & Attribution
No credits recorded in the NVD database.
References
- https://www.cisa.gov/news-events/ics-advisories/icsa-25-162-10
- https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2025/icsa-25-162-10.json
- https://www.cve.org/CVERecord?id=CVE-2025-35452
- https://www.labs.greynoise.io/grimoire/2024-10-31-sift-0-day-rce/
- https://www.greynoise.io/blog/greynoise-intelligence-discovers-zero-day-vulnerabilities-in-live-streaming-cameras-with-the-help-of-ai
More from PTZOptics
View All →CVE-2025-35451
Pan-Tilt-Zoom cameras hard-coded default passwords with SSH and telnet enabled
Critical
9.3
CVE-2024-8957
PTZOptics NDI and SDI Cameras Command Injection via NTP Address Configuration
High
7.2
CVE-2024-8956
PTZOptics NDI and SDI Cameras /cgi-bin/param.cgi Insufficient Authentication
Critical
9.1
Affected Vendor
PTZOptics
View all reports →Affected Software
PT12X-SE-xx-G3, PT12X-LINK-4K-xx, PT20X-SE-xx-G3, PT20X-LINK-4K-xx, PT30X-SE-xx-G3, PT30X-LINK-4K-xx, PT-STUDIOPRO, PT12X-STUDIO-4K-xx-G3, PT20X-STUDIO-4K-xx-G3, PT12X-SDI/NDI-xx, PT12X-USB-xx, PT20X-SDI/NDI-xx, Pan-Tilt-Zoom Cameras, PT30X-SDI/NDI-xx, VL Fixed Camera/NDI Fixed Camera, 12x Fixed Camera/NDI Fixed Camera, 20x Fixed Camera/NDI Fixed Camera, EPTZ Fixed Camera/NDI Fixed Camera, HC-EPTZ-NDI, PT12X-4K-xx-G3, PT20X-4K-xx-G3, PT30X-4K-xx-G3, PT20X-USB-xx
Vulnerable Versions:
0, 9.1.43, 0.0.63, 9.1.32, 0.0.89, 9.1.33, 2.0.71, 9.0.41, 8.1.90, 6.3.70, 6.2.88, 6.3.27, *, 6.3.43, 7.2.94, 7.2.85, 8.1.89, 8.2.14, 0.0.58, 0.0.85, 2.0.64, 6.2.81
Timeline
Official Publish:
September 5th, 2025
Last Modified:
September 8th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H