CVE-2026-75969

Summary

Missing authentication for critical function vulnerability for all PTZOptics cameras and the Firmware Upgrade Tool - Firmware Update modules. A missing authentication vulnerability in the firmware update mechanism of affected PTZOptics cameras allows an unauthenticated user to install modified firmware on the device without administrator credentials.

This vulnerability allows attackers to upload modified firmware to the device without admin credentials. This issue affects:

  • Move 4K 12X before: 0.0.98
  • Move 4K 20X before: 0.1.33
  • Move 4K 30X before: 2.1.17
  • Link 4K 12X before: 0.0.99
  • Link 4K 20X before: 0.1.37
  • Link 4K 30X before: 2.1.18
  • Move SE 12X before: 9.1.66
  • Move SE 20X before: 9.1.44
  • Move SE 30X before: 9.1.46
  • Studio 4K 12X before: 8.3.32
  • Studio 4K 20X before: 8.3.32
  • Studio SE 12X before: 8.3.32
  • Studio SE 20X before: 8.3.32
  • All Generation 2 cameras, including: PT12X-SDI-GY-G2, PT12X-SDI-WH-G2, PT12X-NDI-GY-G2, PT12X-NDI-WH-G2; PT12X-USB-GY-G2, PT12X-USB-WH-G2; PT20X-SDI-GY-G2, PT20X-SDI-WH-G2, PT20X-NDI-GY-G2, PT20X-NDI-WH-G2; PT20X-USB-GY-G2, PT20X-USB-WH-G2; PT30X-SDI-GY-G2, PT30X-SDI-WH-G2, PT30X-NDI-GY-G2, PT30X-NDI-WH-G2; PTVL-ZCAM, PTVL-NDI-ZCAM; PTEPTZ-ZCAM-G2, PTEPTZ-NDI-ZCAM-G2; PT12X-ZCAM, PT12X-NDI-ZCAM; PT20X-ZCAM, PT20X-NDI-ZCAM; Studio Pro - All versions
  • Upgrade Tool - All versions

Affected Software

VendorProductVersion RangeStatus
PTZOpticsMove 4K 12X0 < 0.0.98affected
PTZOpticsMove 4K 20X0 < 0.1.33affected
PTZOpticsMove 4K 30X0 < 2.1.17affected
PTZOpticsLink 4K 12X0 < 0.0.99affected
PTZOpticsLink 4K 20X0 < 0.1.37affected
PTZOpticsLink 4K 30X0 < 2.1.18affected
PTZOpticsMove SE 12X0 < 9.1.66affected
PTZOpticsMove SE 20X0 < 9.1.44affected
PTZOpticsMove SE 30X0 < 9.1.46affected
PTZOpticsStudio 4K 12X0 < 8.3.32affected
PTZOpticsStudio 4K 20X0 < 8.3.32affected
PTZOpticsStudio SE 12X0 < 8.3.32affected
PTZOpticsStudio SE 20X0 < 8.3.32affected
PTZOpticsPT12X-SDI-GY-G2, PT12X-SDI-WH-G2, PT12X-NDI-GY-G2, PT12X-NDI-WH-G20affected
PTZOpticsPT12X-USB-GY-G2, PT12X-USB-WH-G20affected
PTZOpticsPT20X-SDI-GY-G2, PT20X-SDI-WH-G2, PT20X-NDI-GY-G2, PT20X-NDI-WH-G20affected
PTZOpticsPT20X-USB-GY-G2, PT20X-USB-WH-G20affected
PTZOpticsPT30X-SDI-GY-G2, PT30X-SDI-WH-G2, PT30X-NDI-GY-G2, PT30X-NDI-WH-G20affected
PTZOpticsPTVL-ZCAM, PTVL-NDI-ZCAM0affected
PTZOpticsPTEPTZ-ZCAM-G2, PTEPTZ-NDI-ZCAM-G20affected
PTZOpticsPT12X-ZCAM, PT12X-NDI-ZCAM0affected
PTZOpticsPT20X-ZCAM, PT20X-NDI-ZCAM0affected
PTZOpticsStudio Pro0affected
PTZOpticsUpgrade Tool0affected

Weaknesses

  • CWE-306: CWE-306 Missing authentication for critical function

Workarounds

  • Disable network services until the firmware can be updated.
  • Restrict access to the camera to a trusted management VLAN.

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: total

References