CVE-2026-75969 Details
Description
Missing authentication for critical function vulnerability for all PTZOptics cameras and the Firmware Upgrade Tool - Firmware Update modules. A missing authentication vulnerability in the firmware update mechanism of affected PTZOptics cameras allows an unauthenticated user to install modified firmware on the device without administrator credentials. This vulnerability allows attackers to upload modified firmware to the device without admin credentials. This issue affects: * Move 4K 12X before: 0.0.98 * Move 4K 20X before: 0.1.33 * Move 4K 30X before: 2.1.17 * Link 4K 12X before: 0.0.99 * Link 4K 20X before: 0.1.37 * Link 4K 30X before: 2.1.18 * Move SE 12X before: 9.1.66 * Move SE 20X before: 9.1.44 * Move SE 30X before: 9.1.46 * Studio 4K 12X before: 8.3.32 * Studio 4K 20X before: 8.3.32 * Studio SE 12X before: 8.3.32 * Studio SE 20X before: 8.3.32 * All Generation 2 cameras, including: PT12X-SDI-GY-G2, PT12X-SDI-WH-G2, PT12X-NDI-GY-G2, PT12X-NDI-WH-G2; PT12X-USB-GY-G2, PT12X-USB-WH-G2; PT20X-SDI-GY-G2, PT20X-SDI-WH-G2, PT20X-NDI-GY-G2, PT20X-NDI-WH-G2; PT20X-USB-GY-G2, PT20X-USB-WH-G2; PT30X-SDI-GY-G2, PT30X-SDI-WH-G2, PT30X-NDI-GY-G2, PT30X-NDI-WH-G2; PTVL-ZCAM, PTVL-NDI-ZCAM; PTEPTZ-ZCAM-G2, PTEPTZ-NDI-ZCAM-G2; PT12X-ZCAM, PT12X-NDI-ZCAM; PT20X-ZCAM, PT20X-NDI-ZCAM; Studio Pro - All versions * Upgrade Tool - All versions
A vulnerability exists in the firmware update process of PTZOptics cameras and the Firmware Upgrade Tool, allowing an unauthenticated user to install modified firmware without administrative credentials. This issue affects various models and versions of PTZOptics cameras, including the Move 4K series, Link 4K series, Move SE series, Studio 4K series, Studio SE series, all Generation 2 cameras, and the Firmware Upgrade Tool.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 30, 2026CISA-ADP
Assessed Sep 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://psirt.havsys.com/ | 16cac6a8-cc1e-4741-89aa-6b97e2437706 |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | 16cac6a8-cc1e-4741-89aa-6b97e2437706 |
Affected Products
| Product | Versions |
|---|---|
| PTZOptics Move 4K 12X | < 0.0.98 (semver) |
CPE
Remediation
| |
| PTZOptics Move 4K 20X | < 0.1.33 (semver) |
CPE
Remediation
| |
| PTZOptics Move 4K 30X | < 2.1.17 (semver) |
CPE
Remediation
| |
| PTZOptics Link 4K 12X | < 0.0.99 (semver) |
CPE
Remediation
| |
| PTZOptics Link 4K 20X | < 0.1.37 (semver) |
CPE
Remediation
| |
| PTZOptics Link 4K 30X | < 2.1.18 (semver) |
CPE
Remediation
| |
| PTZOptics Move SE 12X | < 9.1.66 (semver) |
CPE
Remediation
| |
| PTZOptics Move SE 20X | < 9.1.44 (semver) |
CPE
Remediation
| |
| PTZOptics Move SE 30X | < 9.1.46 (semver) |
CPE
Remediation
| |
| PTZOptics Studio 4K 12X | < 8.3.32 (semver) |
CPE
Remediation
| |
| PTZOptics Studio 4K 20X | < 8.3.32 (semver) |
CPE
Remediation
| |
| PTZOptics Studio SE 12X | < 8.3.32 (semver) |
CPE
Remediation
| |
| PTZOptics Studio SE 20X | < 8.3.32 (semver) |
CPE
Remediation
| |
| PTZOptics PT12X-SDI-GY-G2 | All versions |
CPE
Remediation
| |
| PTZOptics PT12X-SDI-WH-G2 | All versions |
CPE
Remediation
| |
| PTZOptics PT12X-NDI-GY-G2 | All versions |
CPE
Remediation
| |
| PTZOptics PT12X-NDI-WH-G2 | All versions |
CPE
Remediation
| |
| PTZOptics PT12X-USB-GY-G2 | All versions |
CPE
Remediation
| |
| PTZOptics PT12X-USB-WH-G2 | All versions |
CPE
Remediation
| |
| PTZOptics PT20X-SDI-GY-G2 | All versions |
CPE
Remediation
| |
| PTZOptics PT20X-SDI-WH-G2 | All versions |
CPE
Remediation
| |
| PTZOptics PT20X-NDI-GY-G2 | All versions |
CPE
Remediation
| |
| PTZOptics PT20X-NDI-WH-G2 | All versions |
CPE
Remediation
| |
| PTZOptics PT20X-USB-GY-G2 | All versions |
CPE
Remediation
| |
| PTZOptics PT20X-USB-WH-G2 | All versions |
CPE
Remediation
| |
| PTZOptics PT30X-SDI-GY-G2 | All versions |
CPE
Remediation
| |
| PTZOptics PT30X-SDI-WH-G2 | All versions |
CPE
Remediation
| |
| PTZOptics PT30X-NDI-GY-G2 | All versions |
CPE
Remediation
| |
| PTZOptics PT30X-NDI-WH-G2 | All versions |
CPE
Remediation
| |
| PTZOptics PTVL-ZCAM | All versions |
CPE
Remediation
| |
| PTZOptics PTVL-NDI-ZCAM | All versions |
CPE
Remediation
| |
| PTZOptics PTEPTZ-ZCAM-G2 | All versions |
CPE
Remediation
| |
| PTZOptics PTEPTZ-NDI-ZCAM-G2 | All versions |
CPE
Remediation
| |
| PTZOptics PT12X-ZCAM | All versions |
CPE
Remediation
| |
| PTZOptics PT12X-NDI-ZCAM | All versions |
CPE
Remediation
| |
| PTZOptics PT20X-ZCAM | All versions |
CPE
Remediation
| |
| PTZOptics PT20X-NDI-ZCAM | All versions |
CPE
Remediation
| |
| PTZOptics Studio Pro | All versions |
CPE
Remediation
| |
| PTZOptics Upgrade Tool | All versions |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 30, 2026 | CVE Modified | CISA-ADP |
| Sep 30, 2026 | New CVE Received | 16cac6a8-cc1e-4741-89aa-6b97e2437706 |
Volerion