PTZOptics Missing Authentication in Firmware Upload

Summary

CVECVE-2026-75969
StatePUBLISHED
Assignerhsi
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-09-30 17:16:49 UTC
Updated2026-09-30 21:17:13 UTC
DescriptionMissing authentication for critical function vulnerability for all PTZOptics cameras and the Firmware Upgrade Tool - Firmware Update modules. A missing authentication vulnerability in the firmware update mechanism of affected PTZOptics cameras allows an unauthenticated user to install modified firmware on the device without administrator credentials. This vulnerability allows attackers to upload modified firmware to the device without admin credentials. This issue affects: * Move 4K 12X before: 0.0.98 * Move 4K 20X before: 0.1.33 * Move 4K 30X before: 2.1.17 * Link 4K 12X before: 0.0.99 * Link 4K 20X before: 0.1.37 * Link 4K 30X before: 2.1.18 * Move SE 12X before: 9.1.66 * Move SE 20X before: 9.1.44 * Move SE 30X before: 9.1.46 * Studio 4K 12X before: 8.3.32 * Studio 4K 20X before: 8.3.32 * Studio SE 12X before: 8.3.32 * Studio SE 20X before: 8.3.32 * All Generation 2 cameras, including: PT12X-SDI-GY-G2, PT12X-SDI-WH-G2, PT12X-NDI-GY-G2, PT12X-NDI-WH-G2; PT12X-USB-GY-G2, PT12X-USB-WH-G2; PT20X-SDI-GY-G2, PT20X-SDI-WH-G2, PT20X-NDI-GY-G2, PT20X-NDI-WH-G2; PT20X-USB-GY-G2, PT20X-USB-WH-G2; PT30X-SDI-GY-G2, PT30X-SDI-WH-G2, PT30X-NDI-GY-G2, PT30X-NDI-WH-G2; PTVL-ZCAM, PTVL-NDI-ZCAM; PTEPTZ-ZCAM-G2, PTEPTZ-NDI-ZCAM-G2; PT12X-ZCAM, PT12X-NDI-ZCAM; PT20X-ZCAM, PT20X-NDI-ZCAM; Studio Pro - All versions * Upgrade Tool - All versions

Risk And Classification

Primary CVSS: v4.0 9.1 CRITICAL from 16cac6a8-cc1e-4741-89aa-6b97e2437706

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:U/V:C/RE:L/U:Red

EPSS: 0.005610000 probability, percentile 0.446110000 (date 2026-10-01)

Problem Types: CWE-306 | CWE-306 CWE-306 Missing authentication for critical function


VersionSourceTypeScoreSeverityVector
4.016cac6a8-cc1e-4741-89aa-6b97e2437706Secondary9.1CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U/C...
4.0CNACVSS9.1CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U/R...

CVSS v4.0 Breakdown

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
None
Privileges Required
None
User Interaction
None
Confidentiality
High
Integrity
High
Availability
High
Sub Conf.
High
Sub Integrity
High
Sub Availability
High

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:U/V:C/RE:L/U:Red

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA PTZOptics Move 4K 12X affected 0.0.98 custom Not specified
CNA PTZOptics Move 4K 20X affected 0.1.33 custom Not specified
CNA PTZOptics Move 4K 30X affected 2.1.17 custom Not specified
CNA PTZOptics Link 4K 12X affected 0.0.99 custom Not specified
CNA PTZOptics Link 4K 20X affected 0.1.37 custom Not specified
CNA PTZOptics Link 4K 30X affected 2.1.18 custom Not specified
CNA PTZOptics Move SE 12X affected 9.1.66 custom Not specified
CNA PTZOptics Move SE 20X affected 9.1.44 custom Not specified
CNA PTZOptics Move SE 30X affected 9.1.46 custom Not specified
CNA PTZOptics Studio 4K 12X affected 8.3.32 custom Not specified
CNA PTZOptics Studio 4K 20X affected 8.3.32 custom Not specified
CNA PTZOptics Studio SE 12X affected 8.3.32 custom Not specified
CNA PTZOptics Studio SE 20X affected 8.3.32 custom Not specified
CNA PTZOptics PT12X-SDI-GY-G2 PT12X-SDI-WH-G2 PT12X-NDI-GY-G2 PT12X-NDI-WH-G2 affected custom Not specified
CNA PTZOptics PT12X-USB-GY-G2 PT12X-USB-WH-G2 affected custom Not specified
CNA PTZOptics PT20X-SDI-GY-G2 PT20X-SDI-WH-G2 PT20X-NDI-GY-G2 PT20X-NDI-WH-G2 affected custom Not specified
CNA PTZOptics PT20X-USB-GY-G2 PT20X-USB-WH-G2 affected custom Not specified
CNA PTZOptics PT30X-SDI-GY-G2 PT30X-SDI-WH-G2 PT30X-NDI-GY-G2 PT30X-NDI-WH-G2 affected custom Not specified
CNA PTZOptics PTVL-ZCAM PTVL-NDI-ZCAM affected custom Not specified
CNA PTZOptics PTEPTZ-ZCAM-G2 PTEPTZ-NDI-ZCAM-G2 affected custom Not specified
CNA PTZOptics PT12X-ZCAM PT12X-NDI-ZCAM affected custom Not specified
CNA PTZOptics PT20X-ZCAM PT20X-NDI-ZCAM affected custom Not specified
CNA PTZOptics Studio Pro affected Not specified
CNA PTZOptics Upgrade Tool affected custom Not specified

References

ReferenceSourceLinkTags
psirt.havsys.com 16cac6a8-cc1e-4741-89aa-6b97e2437706 psirt.havsys.com
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

Vendor Comments And Credit

Discovery Credit

CNA: Haverford Systems Inc. & PTZOptics would like to thank Jaroslav Svoboda of CESNET for responsibly reporting this vulnerability. (en)

Additional Advisory Data

Solutions

CNA: ProductRemediationMove 4K 12XUpdate to Firmware 0.0.98.Move 4K 20XUpdate to Firmware 0.1.33.Move 4K 30XUpdate to Firmware 2.1.17.Link 4K 12XUpdate to Firmware 0.0.99.Link 4K 20XUpdate to Firmware 0.1.37.Link 4K 30XUpdate to Firmware 2.1.18.Move SE 12X Update to Firmware 9.1.66.Move SE 20X Update to Firmware 9.1.44.Move SE 30X Update to Firmware 9.1.46.Studio 4K 12XUpdate to Firmware 8.3.32Studio 4K 20XUpdate to Firmware 8.3.32.Studio SE 12XUpdate to Firmware 8.3.32.Studio SE 20XUpdate to Firmware 8.3.32

Workarounds

CNA: * Disable network services until the firmware can be updated. * Restrict access to the camera to a trusted management VLAN.

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report