Ptzoptics manufactures remotely controllable Pan-Tilt-Zoom camera systems for broadcast, event, and surveillance applications, with its vulnerability surface concentrated in embedded firmware and USB control interfaces across product lines including the PT12X and PT20X series. The vendor's observed weaknesses cluster around authentication and command-execution boundaries—hard-coded credentials, missing or improper authentication controls, and OS command injection in control protocols—reflecting the exposure of network-connected device management functions. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ptzoptics over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-8957HIGH PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an OS command injection issue. The camera does not sufficiently validate the ntp_addr configuration value which m | Sep 17, 2024 | 7.2 | 92 | YES | NO |
CVE-2024-8956CRITICAL PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an insufficient authentication issue. The camera does not properly enforce authentication to /cgi-bin/param.cgi w | Sep 17, 2024 | 9.1 | 90 | YES | NO |
CVE-2025-35452CRITICAL PTZOptics and possibly other ValueHD-based pan-tilt-zoom cameras use default, shared credentials for the administrative web interface. | Sep 5, 2025 | 9.8 | 31 | NO | NO |
CVE-2025-35451CRITICAL PTZOptics and possibly other ValueHD-based pan-tilt-zoom cameras use hard-coded, default administrative credentials. The passwords can readily be cracked. Many cameras have SSH or | Sep 5, 2025 | 9.8 | 31 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ptzoptics.
Media articles that mention a CVE ID that affects a product developed by Ptzoptics — matched by CVE ID, not by vendor name.