CVE-2026-75969
9.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U/R:U/V:C/RE:L/U:Red
Summary
Missing authentication for critical function vulnerability for all PTZOptics cameras and the Firmware Upgrade Tool - Firmware Update modules. A missing authentication vulnerability in the firmware update mechanism of affected PTZOptics cameras allows an unauthenticated user to install modified firmware on the device without administrator credentials.
This vulnerability allows attackers to upload modified firmware to the device without admin credentials. This issue affects:
- Move 4K 12X before: 0.0.98
- Move 4K 20X before: 0.1.33
- Move 4K 30X before: 2.1.17
- Link 4K 12X before: 0.0.99
- Link 4K 20X before: 0.1.37
- Link 4K 30X before: 2.1.18
- Move SE 12X before: 9.1.66
- Move SE 20X before: 9.1.44
- Move SE 30X before: 9.1.46
- Studio 4K 12X before: 8.3.32
- Studio 4K 20X before: 8.3.32
- Studio SE 12X before: 8.3.32
- Studio SE 20X before: 8.3.32
- All Generation 2 cameras, including: PT12X-SDI-GY-G2, PT12X-SDI-WH-G2, PT12X-NDI-GY-G2, PT12X-NDI-WH-G2; PT12X-USB-GY-G2, PT12X-USB-WH-G2; PT20X-SDI-GY-G2, PT20X-SDI-WH-G2, PT20X-NDI-GY-G2, PT20X-NDI-WH-G2; PT20X-USB-GY-G2, PT20X-USB-WH-G2; PT30X-SDI-GY-G2, PT30X-SDI-WH-G2, PT30X-NDI-GY-G2, PT30X-NDI-WH-G2; PTVL-ZCAM, PTVL-NDI-ZCAM; PTEPTZ-ZCAM-G2, PTEPTZ-NDI-ZCAM-G2; PT12X-ZCAM, PT12X-NDI-ZCAM; PT20X-ZCAM, PT20X-NDI-ZCAM; Studio Pro - All versions
- Upgrade Tool - All versions
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| PTZOptics | Move 4K 12X | 0 < 0.0.98 | affected |
| PTZOptics | Move 4K 20X | 0 < 0.1.33 | affected |
| PTZOptics | Move 4K 30X | 0 < 2.1.17 | affected |
| PTZOptics | Link 4K 12X | 0 < 0.0.99 | affected |
| PTZOptics | Link 4K 20X | 0 < 0.1.37 | affected |
| PTZOptics | Link 4K 30X | 0 < 2.1.18 | affected |
| PTZOptics | Move SE 12X | 0 < 9.1.66 | affected |
| PTZOptics | Move SE 20X | 0 < 9.1.44 | affected |
| PTZOptics | Move SE 30X | 0 < 9.1.46 | affected |
| PTZOptics | Studio 4K 12X | 0 < 8.3.32 | affected |
| PTZOptics | Studio 4K 20X | 0 < 8.3.32 | affected |
| PTZOptics | Studio SE 12X | 0 < 8.3.32 | affected |
| PTZOptics | Studio SE 20X | 0 < 8.3.32 | affected |
| PTZOptics | PT12X-SDI-GY-G2, PT12X-SDI-WH-G2, PT12X-NDI-GY-G2, PT12X-NDI-WH-G2 | 0 | affected |
| PTZOptics | PT12X-USB-GY-G2, PT12X-USB-WH-G2 | 0 | affected |
| PTZOptics | PT20X-SDI-GY-G2, PT20X-SDI-WH-G2, PT20X-NDI-GY-G2, PT20X-NDI-WH-G2 | 0 | affected |
| PTZOptics | PT20X-USB-GY-G2, PT20X-USB-WH-G2 | 0 | affected |
| PTZOptics | PT30X-SDI-GY-G2, PT30X-SDI-WH-G2, PT30X-NDI-GY-G2, PT30X-NDI-WH-G2 | 0 | affected |
| PTZOptics | PTVL-ZCAM, PTVL-NDI-ZCAM | 0 | affected |
| PTZOptics | PTEPTZ-ZCAM-G2, PTEPTZ-NDI-ZCAM-G2 | 0 | affected |
| PTZOptics | PT12X-ZCAM, PT12X-NDI-ZCAM | 0 | affected |
| PTZOptics | PT20X-ZCAM, PT20X-NDI-ZCAM | 0 | affected |
| PTZOptics | Studio Pro | 0 | affected |
| PTZOptics | Upgrade Tool | 0 | affected |
Weaknesses
- CWE-306: CWE-306 Missing authentication for critical function
Workarounds
- Disable network services until the firmware can be updated.
- Restrict access to the camera to a trusted management VLAN.
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: yes
- Technical Impact: total
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.