CVE-2025-35451

EUVD-2025-27022
PTZOptics and possibly other ValueHD-based pan-tilt-zoom cameras use hard-coded, default administrative credentials. The passwords can readily be cracked. Many cameras have SSH or telnet listening on all interfaces. The passwords cannot be changed by the user, nor can the SSH or telnet service be disabled by the user.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
cisa-cgCNA
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 35%
Affected Products (NVD)
VendorProductVersion
ptzopticspt12x-sdi-xx-g2_firmware
𝑥
≤ 6.3.34
ptzopticspt12x-ndi-xx_firmware
𝑥
≤ 6.3.34
ptzopticspt12x-usb-xx-g2_firmware
𝑥
≤ 6.2.81
ptzopticspt20x-sdi-xx-g2_firmware
𝑥
≤ 6.3.20
ptzopticspt20x-ndi-xx_firmware
𝑥
≤ 6.3.20
ptzopticspt20x-usb-xx-g2_firmware
𝑥
≤ 6.2.73
ptzopticspt30x-sdi-xx-g2_firmware
𝑥
≤ 6.3.30
ptzopticspt30x-ndi-xx_firmware
𝑥
≤ 6.3.30
ptzopticspt12x-zcam_firmware
𝑥
≤ 7.2.76
ptzopticspt20x-zcam_firmware
𝑥
≤ 7.2.82
ptzopticsptvl-zcam_firmware
𝑥
≤ 7.2.79
ptzopticspteptz-zcam-g2_firmware
𝑥
≤ 8.1.81
ptzopticspteptz-ndi-zcam-g2_firmware
𝑥
≤ 8.1.81
ptzopticsvl_fixed_camera_firmware
𝑥
≤ 7.2.94
ptzopticsndi_fixed_camera_firmware
𝑥
≤ 7.2.94
multicam-systemsmcamii_ptz_firmware
*
smtavba30s_firmware
*
smtavba20s_firmware
*
smtavbv20s_firmware
*
smtavbx30s_firmware
*
smtavbx20n_firmware
*
smtavbx20uhd-n_firmware
*
smtavbx20uhd_firmware
*
smtavba30-n_firmware
*
smtavba20-n_firmware
*
smtavba12-n_firmware
*
smtavhd17h-n_firmware
*
smtavbx20s-sh_firmware
*
smtavhd17h_firmware
*
smtavbv30s_firmware
*
smtavba12s_firmware
*
valuehdvx90_firmware
*
valuehdvx720l_firmware
*
valuehdvx752ag_firmware
*
valuehdvx752a_firmware
*
valuehdvx751ba_firmware
*
valuehdvx630al_firmware
*
valuehdvx61asl_firmware
*
valuehdvx61basl_firmware
*
valuehdvx60asl_firmware
*
valuehdvx61al_firmware
*
valuehdvx60al_firmware
*
valuehdvx701ra_firmware
*
valuehdvx701ta_firmware
*
valuehdvx800i2_firmware
*
valuehdv61w_firmware
*
valuehdv63xl_firmware
*
valuehdv60xl_firmware
*
valuehdvx70uvs_firmware
*
valuehdvx71uvs_firmware
*
valuehdv71uvs_firmware
*
𝑥
= Vulnerable software versions