PTZOptics Missing Authentication in Firmware Upload
Summary
| CVE | CVE-2026-75969 |
|---|---|
| State | PUBLISHED |
| Assigner | hsi |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-30 17:16:49 UTC |
| Updated | 2026-09-30 21:17:13 UTC |
| Description | Missing authentication for critical function vulnerability for all PTZOptics cameras and the Firmware Upgrade Tool - Firmware Update modules. A missing authentication vulnerability in the firmware update mechanism of affected PTZOptics cameras allows an unauthenticated user to install modified firmware on the device without administrator credentials. This vulnerability allows attackers to upload modified firmware to the device without admin credentials. This issue affects: * Move 4K 12X before: 0.0.98 * Move 4K 20X before: 0.1.33 * Move 4K 30X before: 2.1.17 * Link 4K 12X before: 0.0.99 * Link 4K 20X before: 0.1.37 * Link 4K 30X before: 2.1.18 * Move SE 12X before: 9.1.66 * Move SE 20X before: 9.1.44 * Move SE 30X before: 9.1.46 * Studio 4K 12X before: 8.3.32 * Studio 4K 20X before: 8.3.32 * Studio SE 12X before: 8.3.32 * Studio SE 20X before: 8.3.32 * All Generation 2 cameras, including: PT12X-SDI-GY-G2, PT12X-SDI-WH-G2, PT12X-NDI-GY-G2, PT12X-NDI-WH-G2; PT12X-USB-GY-G2, PT12X-USB-WH-G2; PT20X-SDI-GY-G2, PT20X-SDI-WH-G2, PT20X-NDI-GY-G2, PT20X-NDI-WH-G2; PT20X-USB-GY-G2, PT20X-USB-WH-G2; PT30X-SDI-GY-G2, PT30X-SDI-WH-G2, PT30X-NDI-GY-G2, PT30X-NDI-WH-G2; PTVL-ZCAM, PTVL-NDI-ZCAM; PTEPTZ-ZCAM-G2, PTEPTZ-NDI-ZCAM-G2; PT12X-ZCAM, PT12X-NDI-ZCAM; PT20X-ZCAM, PT20X-NDI-ZCAM; Studio Pro - All versions * Upgrade Tool - All versions |
Risk And Classification
Primary CVSS: v4.0 9.1 CRITICAL from 16cac6a8-cc1e-4741-89aa-6b97e2437706
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:U/V:C/RE:L/U:Red
EPSS: 0.005610000 probability, percentile 0.446110000 (date 2026-10-01)
Problem Types: CWE-306 | CWE-306 CWE-306 Missing authentication for critical function
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | 16cac6a8-cc1e-4741-89aa-6b97e2437706 | Secondary | 9.1 | CRITICAL | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U/C... |
| 4.0 | CNA | CVSS | 9.1 | CRITICAL | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U/R... |
CVSS v4.0 Breakdown
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:U/V:C/RE:L/U:Red
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | PTZOptics | Move 4K 12X | affected 0.0.98 custom | Not specified |
| CNA | PTZOptics | Move 4K 20X | affected 0.1.33 custom | Not specified |
| CNA | PTZOptics | Move 4K 30X | affected 2.1.17 custom | Not specified |
| CNA | PTZOptics | Link 4K 12X | affected 0.0.99 custom | Not specified |
| CNA | PTZOptics | Link 4K 20X | affected 0.1.37 custom | Not specified |
| CNA | PTZOptics | Link 4K 30X | affected 2.1.18 custom | Not specified |
| CNA | PTZOptics | Move SE 12X | affected 9.1.66 custom | Not specified |
| CNA | PTZOptics | Move SE 20X | affected 9.1.44 custom | Not specified |
| CNA | PTZOptics | Move SE 30X | affected 9.1.46 custom | Not specified |
| CNA | PTZOptics | Studio 4K 12X | affected 8.3.32 custom | Not specified |
| CNA | PTZOptics | Studio 4K 20X | affected 8.3.32 custom | Not specified |
| CNA | PTZOptics | Studio SE 12X | affected 8.3.32 custom | Not specified |
| CNA | PTZOptics | Studio SE 20X | affected 8.3.32 custom | Not specified |
| CNA | PTZOptics | PT12X-SDI-GY-G2 PT12X-SDI-WH-G2 PT12X-NDI-GY-G2 PT12X-NDI-WH-G2 | affected custom | Not specified |
| CNA | PTZOptics | PT12X-USB-GY-G2 PT12X-USB-WH-G2 | affected custom | Not specified |
| CNA | PTZOptics | PT20X-SDI-GY-G2 PT20X-SDI-WH-G2 PT20X-NDI-GY-G2 PT20X-NDI-WH-G2 | affected custom | Not specified |
| CNA | PTZOptics | PT20X-USB-GY-G2 PT20X-USB-WH-G2 | affected custom | Not specified |
| CNA | PTZOptics | PT30X-SDI-GY-G2 PT30X-SDI-WH-G2 PT30X-NDI-GY-G2 PT30X-NDI-WH-G2 | affected custom | Not specified |
| CNA | PTZOptics | PTVL-ZCAM PTVL-NDI-ZCAM | affected custom | Not specified |
| CNA | PTZOptics | PTEPTZ-ZCAM-G2 PTEPTZ-NDI-ZCAM-G2 | affected custom | Not specified |
| CNA | PTZOptics | PT12X-ZCAM PT12X-NDI-ZCAM | affected custom | Not specified |
| CNA | PTZOptics | PT20X-ZCAM PT20X-NDI-ZCAM | affected custom | Not specified |
| CNA | PTZOptics | Studio Pro | affected | Not specified |
| CNA | PTZOptics | Upgrade Tool | affected custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| psirt.havsys.com | 16cac6a8-cc1e-4741-89aa-6b97e2437706 | psirt.havsys.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Haverford Systems Inc. & PTZOptics would like to thank Jaroslav Svoboda of CESNET for responsibly reporting this vulnerability. (en)
Additional Advisory Data
Solutions
CNA: ProductRemediationMove 4K 12XUpdate to Firmware 0.0.98.Move 4K 20XUpdate to Firmware 0.1.33.Move 4K 30XUpdate to Firmware 2.1.17.Link 4K 12XUpdate to Firmware 0.0.99.Link 4K 20XUpdate to Firmware 0.1.37.Link 4K 30XUpdate to Firmware 2.1.18.Move SE 12X Update to Firmware 9.1.66.Move SE 20X Update to Firmware 9.1.44.Move SE 30X Update to Firmware 9.1.46.Studio 4K 12XUpdate to Firmware 8.3.32Studio 4K 20XUpdate to Firmware 8.3.32.Studio SE 12XUpdate to Firmware 8.3.32.Studio SE 20XUpdate to Firmware 8.3.32
Workarounds
CNA: * Disable network services until the firmware can be updated. * Restrict access to the camera to a trusted management VLAN.