CVE-2025-35451 Details
Description
PTZOptics and possibly other ValueHD-based pan-tilt-zoom cameras use hard-coded, default administrative credentials. The passwords can readily be cracked. Many cameras have SSH or telnet listening on all interfaces. The passwords cannot be changed by the user, nor can the SSH or telnet service be disabled by the user.
A vulnerability exists in PTZOptics and other ValueHD-based pan-tilt-zoom cameras, all versions prior to 6.3.40, excluding certain models, which use hard-coded default administrative passwords. These passwords, easily cracked, grant access to the admin web interface and, when combined with other vulnerabilities, allow for remote code execution. Many of these cameras have SSH or telnet enabled by default, listening on all interfaces. The default passwords for SSH and telnet can be easily cracked, but users cannot change these passwords or disable the SSH or telnet services. The vulnerability arises from improper authentication and the use of hard-coded credentials, which can be exploited to access sensitive data and execute arbitrary commands on the devices.
PTZOptics has released firmware updates addressing these vulnerabilities. Affected users should contact ValueHD, multiCAM Systems, or SMTAV for guidance on securing their devices.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Sep 8, 2025CISA-ADP
Assessed Sep 8, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2025/icsa-25-162-10.json | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government | Third Party Advisory |
| https://www.cisa.gov/news-events/ics-advisories/icsa-25-162-10 | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government | Third Party AdvisoryUS Government Resource |
| https://www.cve.org/CVERecord?id=CVE-2025-35451 | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government | Third Party Advisory |
| https://www.greynoise.io/blog/greynoise-intelligence-discovers-zero-day-vulnerabilities-in-live-streaming-cameras-with-the-help-of-ai | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government | Third Party Advisory |
| https://www.labs.greynoise.io/grimoire/2024-10-31-sift-0-day-rce/ | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government | ExploitThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-798 | Use of Hard-coded Credentials | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
Affected Products
| Product | Versions |
|---|---|
| ptzoptics pt12x-sdi-xx-g2 firmware | <= 6.3.34 |
CPE
Remediation
| |
| ptzoptics pt12x-sdi-xx-g2 | All versions |
CPE
Remediation
| |
| ptzoptics pt12x-ndi-xx firmware | <= 6.3.34 |
CPE
Remediation
| |
| ptzoptics pt12x-ndi-xx | All versions |
CPE
Remediation
| |
| ptzoptics pt12x-usb-xx-g2 firmware | <= 6.2.81 |
CPE
Remediation
| |
| ptzoptics pt12x-usb-xx-g2 | All versions |
CPE
Remediation
| |
| ptzoptics pt20x-sdi-xx-g2 firmware | <= 6.3.20 |
CPE
Remediation
| |
| ptzoptics pt20x-sdi-xx-g2 | All versions |
CPE
Remediation
| |
| ptzoptics pt20x-ndi-xx firmware | <= 6.3.20 |
CPE
Remediation
| |
| ptzoptics pt20x-ndi-xx | All versions |
CPE
Remediation
| |
| ptzoptics pt20x-usb-xx-g2 firmware | <= 6.2.73 |
CPE
Remediation
| |
| ptzoptics pt20x-usb-xx-g2 | All versions |
CPE
Remediation
| |
| ptzoptics pt30x-sdi-xx-g2 firmware | <= 6.3.30 |
CPE
Remediation
| |
| ptzoptics pt30x-sdi-xx-g2 | All versions |
CPE
Remediation
| |
| ptzoptics pt30x-ndi-xx firmware | <= 6.3.30 |
CPE
Remediation
| |
| ptzoptics pt30x-ndi-xx | All versions |
CPE
Remediation
| |
| ptzoptics pt12x-zcam firmware | <= 7.2.76 |
CPE
Remediation
| |
| ptzoptics pt12x-zcam | All versions |
CPE
Remediation
| |
| ptzoptics pt20x-zcam firmware | <= 7.2.82 |
CPE
Remediation
| |
| ptzoptics pt20x-zcam | All versions |
CPE
Remediation
| |
| ptzoptics ptvl-zcam firmware | <= 7.2.79 |
CPE
Remediation
| |
| ptzoptics ptvl-zcam | All versions |
CPE
Remediation
| |
| ptzoptics pteptz-zcam-g2 firmware | <= 8.1.81 |
CPE
Remediation
| |
| ptzoptics pteptz-zcam-g2 | All versions |
CPE
Remediation
| |
| ptzoptics pteptz-ndi-zcam-g2 firmware | <= 8.1.81 |
CPE
Remediation
| |
| ptzoptics pteptz-ndi-zcam-g2 | All versions |
CPE
Remediation
| |
| ptzoptics vl fixed camera firmware | <= 7.2.94 |
CPE
Remediation
| |
| ptzoptics vl fixed camera | All versions |
CPE
Remediation
| |
| ptzoptics ndi fixed camera firmware | <= 7.2.94 |
CPE
Remediation
| |
| ptzoptics ndi fixed camera | All versions |
CPE
Remediation
| |
| multicam-systems mcamii ptz firmware | All versions |
CPE
Remediation
| |
| multicam-systems mcamii ptz | All versions |
CPE
Remediation
| |
| smtav ba30s firmware | All versions |
CPE
Remediation
| |
| smtav ba30s | All versions |
CPE
Remediation
| |
| smtav ba20s firmware | All versions |
CPE
Remediation
| |
| smtav ba20s | All versions |
CPE
Remediation
| |
| smtav bv20s firmware | All versions |
CPE
Remediation
| |
| smtav bv20s | All versions |
CPE
Remediation
| |
| smtav bx30s firmware | All versions |
CPE
Remediation
| |
| smtav bx30s | All versions |
CPE
Remediation
| |
| smtav bx20n firmware | All versions |
CPE
Remediation
| |
| smtav bx20n | All versions |
CPE
Remediation
| |
| smtav bx20uhd-n firmware | All versions |
CPE
Remediation
| |
| smtav bx20uhd-n | All versions |
CPE
Remediation
| |
| smtav bx20uhd firmware | All versions |
CPE
Remediation
| |
| smtav bx20uhd | All versions |
CPE
Remediation
| |
| smtav ba30-n firmware | All versions |
CPE
Remediation
| |
| smtav ba30-n | All versions |
CPE
Remediation
| |
| smtav ba20-n firmware | All versions |
CPE
Remediation
| |
| smtav ba20-n | All versions |
CPE
Remediation
| |
| smtav ba12-n firmware | All versions |
CPE
Remediation
| |
| smtav ba12-n | All versions |
CPE
Remediation
| |
| smtav hd17h-n firmware | All versions |
CPE
Remediation
| |
| smtav hd17h-n | All versions |
CPE
Remediation
| |
| smtav bx20s-sh firmware | All versions |
CPE
Remediation
| |
| smtav bx20s-sh | All versions |
CPE
Remediation
| |
| smtav hd17h firmware | All versions |
CPE
Remediation
| |
| smtav hd17h | All versions |
CPE
Remediation
| |
| smtav bv30s firmware | All versions |
CPE
Remediation
| |
| smtav bv30s | All versions |
CPE
Remediation
| |
| smtav ba12s firmware | All versions |
CPE
Remediation
| |
| smtav ba12s | All versions |
CPE
Remediation
| |
| valuehd vx90 firmware | All versions |
CPE
Remediation
| |
| valuehd vx90 | All versions |
CPE
Remediation
| |
| valuehd vx720l firmware | All versions |
CPE
Remediation
| |
| valuehd vx720l | All versions |
CPE
Remediation
| |
| valuehd vx752ag firmware | All versions |
CPE
Remediation
| |
| valuehd vx752ag | All versions |
CPE
Remediation
| |
| valuehd vx752a firmware | All versions |
CPE
Remediation
| |
| valuehd vx752a | All versions |
CPE
Remediation
| |
| valuehd vx751ba firmware | All versions |
CPE
Remediation
| |
| valuehd vx751ba | All versions |
CPE
Remediation
| |
| valuehd vx630al firmware | All versions |
CPE
Remediation
| |
| valuehd vx630al | All versions |
CPE
Remediation
| |
| valuehd vx61asl firmware | All versions |
CPE
Remediation
| |
| valuehd vx61asl | All versions |
CPE
Remediation
| |
| valuehd vx61basl firmware | All versions |
CPE
Remediation
| |
| valuehd vx61basl | All versions |
CPE
Remediation
| |
| valuehd vx60asl firmware | All versions |
CPE
Remediation
| |
| valuehd vx60asl | All versions |
CPE
Remediation
| |
| valuehd vx61al firmware | All versions |
CPE
Remediation
| |
| valuehd vx61al | All versions |
CPE
Remediation
| |
| valuehd vx60al firmware | All versions |
CPE
Remediation
| |
| valuehd vx60al | All versions |
CPE
Remediation
| |
| valuehd vx701ra firmware | All versions |
CPE
Remediation
| |
| valuehd vx701ra | All versions |
CPE
Remediation
| |
| valuehd vx701ta firmware | All versions |
CPE
Remediation
| |
| valuehd vx701ta | All versions |
CPE
Remediation
| |
| valuehd vx800i2 firmware | All versions |
CPE
Remediation
| |
| valuehd vx800i2 | All versions |
CPE
Remediation
| |
| valuehd v61w firmware | All versions |
CPE
Remediation
| |
| valuehd v61w | All versions |
CPE
Remediation
| |
| valuehd v63xl firmware | All versions |
CPE
Remediation
| |
| valuehd v63xl | All versions |
CPE
Remediation
| |
| valuehd v60xl firmware | All versions |
CPE
Remediation
| |
| valuehd v60xl | All versions |
CPE
Remediation
| |
| valuehd vx70uvs firmware | All versions |
CPE
Remediation
| |
| valuehd vx70uvs | All versions |
CPE
Remediation
| |
| valuehd vx71uvs firmware | All versions |
CPE
Remediation
| |
| valuehd vx71uvs | All versions |
CPE
Remediation
| |
| valuehd v71uvs firmware | All versions |
CPE
Remediation
| |
| valuehd v71uvs | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 14, 2026 | Initial Analysis | [email protected] |
| Sep 5, 2025 | CVE Modified | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
| Sep 5, 2025 | New CVE Received | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |