9.1

CVE-2026-75969

PTZOptics Missing Authentication in Firmware Upload

Missing authentication for critical function vulnerability for all PTZOptics cameras and the Firmware Upgrade Tool - Firmware Update modules. A missing authentication vulnerability in the firmware update mechanism of affected PTZOptics cameras allows an unauthenticated user to install modified firmware on the device without administrator credentials.



This vulnerability allows attackers to upload modified firmware to the device without admin credentials. This issue affects:





  *  Move 4K 12X before: 0.0.98
  *  Move 4K 20X before: 0.1.33
  *  Move 4K 30X before: 2.1.17
  *  Link 4K 12X before: 0.0.99
  *  Link 4K 20X before: 0.1.37
  *  Link 4K 30X before: 2.1.18
  *  Move SE 12X before: 9.1.66
  *  Move SE 20X before: 9.1.44
  *  Move SE 30X before: 9.1.46
  *  Studio 4K 12X before: 8.3.32
  *  Studio 4K 20X before: 8.3.32
  *  Studio SE 12X before: 8.3.32
  *  Studio SE 20X before: 8.3.32
  *  All Generation 2 cameras, including: PT12X-SDI-GY-G2, PT12X-SDI-WH-G2, PT12X-NDI-GY-G2, PT12X-NDI-WH-G2; PT12X-USB-GY-G2, PT12X-USB-WH-G2; PT20X-SDI-GY-G2, PT20X-SDI-WH-G2, PT20X-NDI-GY-G2, PT20X-NDI-WH-G2; PT20X-USB-GY-G2, PT20X-USB-WH-G2; PT30X-SDI-GY-G2, PT30X-SDI-WH-G2, PT30X-NDI-GY-G2, PT30X-NDI-WH-G2; PTVL-ZCAM, PTVL-NDI-ZCAM; PTEPTZ-ZCAM-G2, PTEPTZ-NDI-ZCAM-G2; PT12X-ZCAM, PT12X-NDI-ZCAM; PT20X-ZCAM, PT20X-NDI-ZCAM; Studio Pro - All versions
  *  Upgrade Tool - All versions
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerPTZOptics
≫
Produkt Move 4K 12X
Default Statusunaffected
Version 0
Version < 0.0.98
Status affected
HerstellerPTZOptics
≫
Produkt Move 4K 20X
Default Statusunaffected
Version 0
Version < 0.1.33
Status affected
HerstellerPTZOptics
≫
Produkt Move 4K 30X
Default Statusunaffected
Version 0
Version < 2.1.17
Status affected
HerstellerPTZOptics
≫
Produkt Link 4K 12X
Default Statusunaffected
Version 0
Version < 0.0.99
Status affected
HerstellerPTZOptics
≫
Produkt Link 4K 20X
Default Statusunaffected
Version 0
Version < 0.1.37
Status affected
HerstellerPTZOptics
≫
Produkt Link 4K 30X
Default Statusunaffected
Version 0
Version < 2.1.18
Status affected
HerstellerPTZOptics
≫
Produkt Move SE 12X
Default Statusunaffected
Version 0
Version < 9.1.66
Status affected
HerstellerPTZOptics
≫
Produkt Move SE 20X
Default Statusunaffected
Version 0
Version < 9.1.44
Status affected
HerstellerPTZOptics
≫
Produkt Move SE 30X
Default Statusunaffected
Version 0
Version < 9.1.46
Status affected
HerstellerPTZOptics
≫
Produkt Studio 4K 12X
Default Statusunaffected
Version 0
Version < 8.3.32
Status affected
HerstellerPTZOptics
≫
Produkt Studio 4K 20X
Default Statusunaffected
Version 0
Version < 8.3.32
Status affected
HerstellerPTZOptics
≫
Produkt Studio SE 12X
Default Statusunaffected
Version 0
Version < 8.3.32
Status affected
HerstellerPTZOptics
≫
Produkt Studio SE 20X
Default Statusunaffected
Version 0
Version < 8.3.32
Status affected
HerstellerPTZOptics
≫
Produkt PT12X-SDI-GY-G2, PT12X-SDI-WH-G2, PT12X-NDI-GY-G2, PT12X-NDI-WH-G2
Default Statusaffected
Version 0
Status affected
HerstellerPTZOptics
≫
Produkt PT12X-USB-GY-G2, PT12X-USB-WH-G2
Default Statusaffected
Version 0
Status affected
HerstellerPTZOptics
≫
Produkt PT20X-SDI-GY-G2, PT20X-SDI-WH-G2, PT20X-NDI-GY-G2, PT20X-NDI-WH-G2
Default Statusaffected
Version 0
Status affected
HerstellerPTZOptics
≫
Produkt PT20X-USB-GY-G2, PT20X-USB-WH-G2
Default Statusaffected
Version 0
Status affected
HerstellerPTZOptics
≫
Produkt PT30X-SDI-GY-G2, PT30X-SDI-WH-G2, PT30X-NDI-GY-G2, PT30X-NDI-WH-G2
Default Statusaffected
Version 0
Status affected
HerstellerPTZOptics
≫
Produkt PTVL-ZCAM, PTVL-NDI-ZCAM
Default Statusaffected
Version 0
Status affected
HerstellerPTZOptics
≫
Produkt PTEPTZ-ZCAM-G2, PTEPTZ-NDI-ZCAM-G2
Default Statusaffected
Version 0
Status affected
HerstellerPTZOptics
≫
Produkt PT12X-ZCAM, PT12X-NDI-ZCAM
Default Statusaffected
Version 0
Status affected
HerstellerPTZOptics
≫
Produkt PT20X-ZCAM, PT20X-NDI-ZCAM
Default Statusaffected
Version 0
Status affected
HerstellerPTZOptics
≫
Produkt Studio Pro
Default Statusaffected
Version 0
Status affected
HerstellerPTZOptics
≫
Produkt Upgrade Tool
Default Statusaffected
Version 0
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.35% 0.263
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
16cac6a8-cc1e-4741-89aa-6b97e2437706 9.1 0 0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:U/V:C/RE:L/U:Red
CWE-306 Missing Authentication for Critical Function

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.