{"api_version":"1","generated_at":"2026-10-01T18:35:09+00:00","cve":"CVE-2026-75969","urls":{"html":"https://cve.report/CVE-2026-75969","api":"https://cve.report/api/cve/CVE-2026-75969.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-75969","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-75969"},"summary":{"title":"PTZOptics Missing Authentication in Firmware Upload","description":"Missing authentication for critical function vulnerability for all PTZOptics cameras and the Firmware Upgrade Tool - Firmware Update modules. A missing authentication vulnerability in the firmware update mechanism of affected PTZOptics cameras allows an unauthenticated user to install modified firmware on the device without administrator credentials.\n\n\n\nThis vulnerability allows attackers to upload modified firmware to the device without admin credentials. This issue affects:\n\n\n\n\n\n  *  Move 4K 12X before: 0.0.98\n  *  Move 4K 20X before: 0.1.33\n  *  Move 4K 30X before: 2.1.17\n  *  Link 4K 12X before: 0.0.99\n  *  Link 4K 20X before: 0.1.37\n  *  Link 4K 30X before: 2.1.18\n  *  Move SE 12X before: 9.1.66\n  *  Move SE 20X before: 9.1.44\n  *  Move SE 30X before: 9.1.46\n  *  Studio 4K 12X before: 8.3.32\n  *  Studio 4K 20X before: 8.3.32\n  *  Studio SE 12X before: 8.3.32\n  *  Studio SE 20X before: 8.3.32\n  *  All Generation 2 cameras, including: PT12X-SDI-GY-G2, PT12X-SDI-WH-G2, PT12X-NDI-GY-G2, PT12X-NDI-WH-G2; PT12X-USB-GY-G2, PT12X-USB-WH-G2; PT20X-SDI-GY-G2, PT20X-SDI-WH-G2, PT20X-NDI-GY-G2, PT20X-NDI-WH-G2; PT20X-USB-GY-G2, PT20X-USB-WH-G2; PT30X-SDI-GY-G2, PT30X-SDI-WH-G2, PT30X-NDI-GY-G2, PT30X-NDI-WH-G2; PTVL-ZCAM, PTVL-NDI-ZCAM; PTEPTZ-ZCAM-G2, PTEPTZ-NDI-ZCAM-G2; PT12X-ZCAM, PT12X-NDI-ZCAM; PT20X-ZCAM, PT20X-NDI-ZCAM; Studio Pro - All versions\n  *  Upgrade Tool - All versions","state":"PUBLISHED","assigner":"hsi","published_at":"2026-09-30 17:16:49","updated_at":"2026-09-30 21:17:13"},"problem_types":["CWE-306","CWE-306 CWE-306 Missing authentication for critical function"],"metrics":[{"version":"4.0","source":"16cac6a8-cc1e-4741-89aa-6b97e2437706","type":"Secondary","score":"9.1","severity":"CRITICAL","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:U/V:C/RE:L/U:Red","data":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:U/V:C/RE:L/U:Red","baseScore":9.1,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"HIGH","subIntegrityImpact":"HIGH","subAvailabilityImpact":"HIGH","exploitMaturity":"UNREPORTED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"USER","valueDensity":"CONCENTRATED","vulnerabilityResponseEffort":"LOW","providerUrgency":"RED"}},{"version":"4.0","source":"CNA","type":"CVSS","score":"9.1","severity":"CRITICAL","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U/R:U/V:C/RE:L/U:Red","data":{"Automatable":"NOT_DEFINED","Recovery":"USER","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":9.1,"baseSeverity":"CRITICAL","exploitMaturity":"UNREPORTED","privilegesRequired":"NONE","providerUrgency":"RED","subAvailabilityImpact":"HIGH","subConfidentialityImpact":"HIGH","subIntegrityImpact":"HIGH","userInteraction":"NONE","valueDensity":"CONCENTRATED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U/R:U/V:C/RE:L/U:Red","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnerabilityResponseEffort":"LOW"}}],"references":[{"url":"https://psirt.havsys.com/","name":"https://psirt.havsys.com/","refsource":"16cac6a8-cc1e-4741-89aa-6b97e2437706","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-75969","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-75969","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"PTZOptics","product":"Move 4K 12X","version":"affected 0.0.98 custom","platforms":[]},{"source":"CNA","vendor":"PTZOptics","product":"Move 4K 20X","version":"affected 0.1.33 custom","platforms":[]},{"source":"CNA","vendor":"PTZOptics","product":"Move 4K 30X","version":"affected 2.1.17 custom","platforms":[]},{"source":"CNA","vendor":"PTZOptics","product":"Link 4K 12X","version":"affected 0.0.99 custom","platforms":[]},{"source":"CNA","vendor":"PTZOptics","product":"Link 4K 20X","version":"affected 0.1.37 custom","platforms":[]},{"source":"CNA","vendor":"PTZOptics","product":"Link 4K 30X","version":"affected 2.1.18 custom","platforms":[]},{"source":"CNA","vendor":"PTZOptics","product":"Move SE 12X","version":"affected 9.1.66 custom","platforms":[]},{"source":"CNA","vendor":"PTZOptics","product":"Move SE 20X","version":"affected 9.1.44 custom","platforms":[]},{"source":"CNA","vendor":"PTZOptics","product":"Move SE 30X","version":"affected 9.1.46 custom","platforms":[]},{"source":"CNA","vendor":"PTZOptics","product":"Studio 4K 12X","version":"affected 8.3.32 custom","platforms":[]},{"source":"CNA","vendor":"PTZOptics","product":"Studio 4K 20X","version":"affected 8.3.32 custom","platforms":[]},{"source":"CNA","vendor":"PTZOptics","product":"Studio SE 12X","version":"affected 8.3.32 custom","platforms":[]},{"source":"CNA","vendor":"PTZOptics","product":"Studio SE 20X","version":"affected 8.3.32 custom","platforms":[]},{"source":"CNA","vendor":"PTZOptics","product":"PT12X-SDI-GY-G2, PT12X-SDI-WH-G2, PT12X-NDI-GY-G2, PT12X-NDI-WH-G2","version":"affected custom","platforms":[]},{"source":"CNA","vendor":"PTZOptics","product":"PT12X-USB-GY-G2, PT12X-USB-WH-G2","version":"affected custom","platforms":[]},{"source":"CNA","vendor":"PTZOptics","product":"PT20X-SDI-GY-G2, PT20X-SDI-WH-G2, PT20X-NDI-GY-G2, PT20X-NDI-WH-G2","version":"affected custom","platforms":[]},{"source":"CNA","vendor":"PTZOptics","product":"PT20X-USB-GY-G2, PT20X-USB-WH-G2","version":"affected custom","platforms":[]},{"source":"CNA","vendor":"PTZOptics","product":"PT30X-SDI-GY-G2, PT30X-SDI-WH-G2, PT30X-NDI-GY-G2, PT30X-NDI-WH-G2","version":"affected custom","platforms":[]},{"source":"CNA","vendor":"PTZOptics","product":"PTVL-ZCAM, PTVL-NDI-ZCAM","version":"affected custom","platforms":[]},{"source":"CNA","vendor":"PTZOptics","product":"PTEPTZ-ZCAM-G2, PTEPTZ-NDI-ZCAM-G2","version":"affected custom","platforms":[]},{"source":"CNA","vendor":"PTZOptics","product":"PT12X-ZCAM, PT12X-NDI-ZCAM","version":"affected custom","platforms":[]},{"source":"CNA","vendor":"PTZOptics","product":"PT20X-ZCAM, PT20X-NDI-ZCAM","version":"affected custom","platforms":[]},{"source":"CNA","vendor":"PTZOptics","product":"Studio Pro","version":"affected","platforms":[]},{"source":"CNA","vendor":"PTZOptics","product":"Upgrade Tool","version":"affected custom","platforms":[]}],"timeline":[],"solutions":[{"source":"CNA","title":"","value":"ProductRemediationMove 4K 12XUpdate to Firmware 0.0.98.Move 4K 20XUpdate to Firmware 0.1.33.Move 4K 30XUpdate to Firmware 2.1.17.Link 4K 12XUpdate to Firmware 0.0.99.Link 4K 20XUpdate to Firmware 0.1.37.Link 4K 30XUpdate to Firmware 2.1.18.Move SE 12X Update to Firmware 9.1.66.Move SE 20X Update to Firmware 9.1.44.Move SE 30X Update to Firmware 9.1.46.Studio 4K 12XUpdate to Firmware 8.3.32Studio 4K 20XUpdate to Firmware 8.3.32.Studio SE 12XUpdate to Firmware 8.3.32.Studio SE 20XUpdate to Firmware 8.3.32","time":"","lang":"en"}],"workarounds":[{"source":"CNA","title":"","value":"*  Disable network services until the firmware can be updated.\n  *  Restrict access to the camera to a trusted management VLAN.","time":"","lang":"en"}],"exploits":[],"credits":[{"source":"CNA","value":"Haverford Systems Inc. & PTZOptics would like to thank Jaroslav Svoboda of CESNET for responsibly reporting this vulnerability.","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-75969","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"total"}],"role":"CISA Coordinator","timestamp":"2026-09-30T18:30:11.739848Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-09-30T20:01:02.432Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"unaffected","modules":["Firmware Update"],"product":"Move 4K 12X","vendor":"PTZOptics","versions":[{"lessThan":"0.0.98","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unaffected","modules":["Firmware Update"],"product":"Move 4K 20X","vendor":"PTZOptics","versions":[{"lessThan":"0.1.33","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unaffected","modules":["Firmware Update"],"product":"Move 4K 30X","vendor":"PTZOptics","versions":[{"lessThan":"2.1.17","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unaffected","modules":["Firmware Update"],"product":"Link 4K 12X","vendor":"PTZOptics","versions":[{"lessThan":"0.0.99","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unaffected","modules":["Firmware Update"],"product":"Link 4K 20X","vendor":"PTZOptics","versions":[{"lessThan":"0.1.37","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unaffected","modules":["Firmware Update"],"product":"Link 4K 30X","vendor":"PTZOptics","versions":[{"lessThan":"2.1.18","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unaffected","modules":["Firmware Update"],"product":"Move SE 12X","vendor":"PTZOptics","versions":[{"lessThan":"9.1.66","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unaffected","modules":["Firmware Update"],"product":"Move SE 20X","vendor":"PTZOptics","versions":[{"lessThan":"9.1.44","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unaffected","modules":["Firmware Update"],"product":"Move SE 30X","vendor":"PTZOptics","versions":[{"lessThan":"9.1.46","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unaffected","modules":["Firmware Update"],"product":"Studio 4K 12X","vendor":"PTZOptics","versions":[{"lessThan":"8.3.32","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unaffected","modules":["Firmware Update"],"product":"Studio 4K 20X","vendor":"PTZOptics","versions":[{"lessThan":"8.3.32","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unaffected","modules":["Firmware Update"],"product":"Studio SE 12X","vendor":"PTZOptics","versions":[{"lessThan":"8.3.32","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unaffected","modules":["Firmware Update"],"product":"Studio SE 20X","vendor":"PTZOptics","versions":[{"lessThan":"8.3.32","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"affected","modules":["Firmware Update"],"product":"PT12X-SDI-GY-G2, PT12X-SDI-WH-G2, PT12X-NDI-GY-G2, PT12X-NDI-WH-G2","vendor":"PTZOptics","versions":[{"status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"affected","modules":["Firmware Update"],"product":"PT12X-USB-GY-G2, PT12X-USB-WH-G2","vendor":"PTZOptics","versions":[{"status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"affected","modules":["Firmware Update"],"product":"PT20X-SDI-GY-G2, PT20X-SDI-WH-G2, PT20X-NDI-GY-G2, PT20X-NDI-WH-G2","vendor":"PTZOptics","versions":[{"status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"affected","modules":["Firmware Update"],"product":"PT20X-USB-GY-G2, PT20X-USB-WH-G2","vendor":"PTZOptics","versions":[{"status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"affected","modules":["Firmware Update"],"product":"PT30X-SDI-GY-G2, PT30X-SDI-WH-G2, PT30X-NDI-GY-G2, PT30X-NDI-WH-G2","vendor":"PTZOptics","versions":[{"status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"affected","modules":["Firmware Update"],"product":"PTVL-ZCAM, PTVL-NDI-ZCAM","vendor":"PTZOptics","versions":[{"status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"affected","modules":["Firmware Update"],"product":"PTEPTZ-ZCAM-G2, PTEPTZ-NDI-ZCAM-G2","vendor":"PTZOptics","versions":[{"status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"affected","modules":["Firmware Update"],"product":"PT12X-ZCAM, PT12X-NDI-ZCAM","vendor":"PTZOptics","versions":[{"status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"affected","modules":["Firmware Update"],"product":"PT20X-ZCAM, PT20X-NDI-ZCAM","vendor":"PTZOptics","versions":[{"status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"affected","product":"Studio Pro","vendor":"PTZOptics","versions":[{"status":"affected","version":"0"}]},{"defaultStatus":"affected","modules":["Firmware Update"],"product":"Upgrade Tool","vendor":"PTZOptics","versions":[{"status":"affected","version":"0","versionType":"custom"}]}],"credits":[{"lang":"en","type":"finder","value":"Haverford Systems Inc. & PTZOptics would like to thank Jaroslav Svoboda of CESNET for responsibly reporting this vulnerability."}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>Missing authentication for critical function vulnerability for all PTZOptics cameras and the Firmware Upgrade Tool - Firmware Update modules. A missing authentication vulnerability in the firmware update mechanism of affected PTZOptics cameras allows an unauthenticated user to install modified firmware on the device without administrator credentials.\n<br>\n<br>This vulnerability allows attackers to upload modified firmware to the device without admin credentials. This issue affects:</p><p></p><ul><li>Move 4K 12X before: 0.0.98</li><li>Move 4K 20X before: 0.1.33</li><li>Move 4K 30X before: 2.1.17</li><li>Link 4K 12X before: 0.0.99</li><li>Link 4K 20X before: 0.1.37</li><li>Link 4K 30X before: 2.1.18</li><li>Move SE 12X before: 9.1.66</li><li>Move SE 20X before: 9.1.44</li><li>Move SE 30X before: 9.1.46</li><li>Studio 4K 12X before: 8.3.32</li><li>Studio 4K 20X before: 8.3.32</li><li>Studio SE 12X before: 8.3.32</li><li>Studio SE 20X before: 8.3.32</li><li>All Generation 2 cameras, including: PT12X-SDI-GY-G2, PT12X-SDI-WH-G2, PT12X-NDI-GY-G2, PT12X-NDI-WH-G2; PT12X-USB-GY-G2, PT12X-USB-WH-G2; PT20X-SDI-GY-G2, PT20X-SDI-WH-G2, PT20X-NDI-GY-G2, PT20X-NDI-WH-G2; PT20X-USB-GY-G2, PT20X-USB-WH-G2; PT30X-SDI-GY-G2, PT30X-SDI-WH-G2, PT30X-NDI-GY-G2, PT30X-NDI-WH-G2; PTVL-ZCAM, PTVL-NDI-ZCAM; PTEPTZ-ZCAM-G2, PTEPTZ-NDI-ZCAM-G2; PT12X-ZCAM, PT12X-NDI-ZCAM; PT20X-ZCAM, PT20X-NDI-ZCAM; Studio Pro - All versions</li><li>Upgrade Tool - All versions&nbsp;<br></li></ul><p></p>"}],"value":"Missing authentication for critical function vulnerability for all PTZOptics cameras and the Firmware Upgrade Tool - Firmware Update modules. A missing authentication vulnerability in the firmware update mechanism of affected PTZOptics cameras allows an unauthenticated user to install modified firmware on the device without administrator credentials.\n\n\n\nThis vulnerability allows attackers to upload modified firmware to the device without admin credentials. This issue affects:\n\n\n\n\n\n  *  Move 4K 12X before: 0.0.98\n  *  Move 4K 20X before: 0.1.33\n  *  Move 4K 30X before: 2.1.17\n  *  Link 4K 12X before: 0.0.99\n  *  Link 4K 20X before: 0.1.37\n  *  Link 4K 30X before: 2.1.18\n  *  Move SE 12X before: 9.1.66\n  *  Move SE 20X before: 9.1.44\n  *  Move SE 30X before: 9.1.46\n  *  Studio 4K 12X before: 8.3.32\n  *  Studio 4K 20X before: 8.3.32\n  *  Studio SE 12X before: 8.3.32\n  *  Studio SE 20X before: 8.3.32\n  *  All Generation 2 cameras, including: PT12X-SDI-GY-G2, PT12X-SDI-WH-G2, PT12X-NDI-GY-G2, PT12X-NDI-WH-G2; PT12X-USB-GY-G2, PT12X-USB-WH-G2; PT20X-SDI-GY-G2, PT20X-SDI-WH-G2, PT20X-NDI-GY-G2, PT20X-NDI-WH-G2; PT20X-USB-GY-G2, PT20X-USB-WH-G2; PT30X-SDI-GY-G2, PT30X-SDI-WH-G2, PT30X-NDI-GY-G2, PT30X-NDI-WH-G2; PTVL-ZCAM, PTVL-NDI-ZCAM; PTEPTZ-ZCAM-G2, PTEPTZ-NDI-ZCAM-G2; PT12X-ZCAM, PT12X-NDI-ZCAM; PT20X-ZCAM, PT20X-NDI-ZCAM; Studio Pro - All versions\n  *  Upgrade Tool - All versions"}],"impacts":[{"capecId":"CAPEC-638","descriptions":[{"lang":"en","value":"CAPEC-638 Altered Component Firmware"}]},{"capecId":"CAPEC-669","descriptions":[{"lang":"en","value":"CAPEC-669 Alteration of a Software Update"}]}],"metrics":[{"cvssV4_0":{"Automatable":"NOT_DEFINED","Recovery":"USER","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":9.1,"baseSeverity":"CRITICAL","exploitMaturity":"UNREPORTED","privilegesRequired":"NONE","providerUrgency":"RED","subAvailabilityImpact":"HIGH","subConfidentialityImpact":"HIGH","subIntegrityImpact":"HIGH","userInteraction":"NONE","valueDensity":"CONCENTRATED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U/R:U/V:C/RE:L/U:Red","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnerabilityResponseEffort":"LOW"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-306","description":"CWE-306 Missing authentication for critical function","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-30T16:27:51.490Z","orgId":"16cac6a8-cc1e-4741-89aa-6b97e2437706","shortName":"hsi"},"references":[{"url":"https://psirt.havsys.com/"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<table><tbody><tr><td><b>Product</b></td><td><b>Remediation</b></td></tr><tr><td>Move 4K 12X</td><td>Update to Firmware 0.0.98.</td></tr><tr><td>Move 4K 20X</td><td>Update to Firmware 0.1.33.</td></tr><tr><td>Move 4K 30X</td><td>Update to Firmware 2.1.17.</td></tr><tr><td>Link 4K 12X</td><td>Update to Firmware 0.0.99.</td></tr><tr><td>Link 4K 20X</td><td>Update to Firmware 0.1.37.</td></tr><tr><td>Link 4K 30X</td><td>Update to Firmware 2.1.18.</td></tr><tr><td>Move SE 12X&nbsp;</td><td>Update to Firmware 9.1.66.</td></tr><tr><td>Move SE 20X&nbsp;</td><td>Update to Firmware 9.1.44.</td></tr><tr><td>Move SE 30X&nbsp;</td><td>Update to Firmware 9.1.46.</td></tr><tr><td>Studio 4K 12X</td><td>Update to Firmware 8.3.32</td></tr><tr><td>Studio 4K 20X</td><td>Update to Firmware 8.3.32.</td></tr><tr><td>Studio SE 12X</td><td>Update to Firmware 8.3.32.</td></tr><tr><td>Studio SE 20X</td><td>Update to Firmware 8.3.32</td></tr></tbody></table><p><br></p>"}],"value":"ProductRemediationMove 4K 12XUpdate to Firmware 0.0.98.Move 4K 20XUpdate to Firmware 0.1.33.Move 4K 30XUpdate to Firmware 2.1.17.Link 4K 12XUpdate to Firmware 0.0.99.Link 4K 20XUpdate to Firmware 0.1.37.Link 4K 30XUpdate to Firmware 2.1.18.Move SE 12X Update to Firmware 9.1.66.Move SE 20X Update to Firmware 9.1.44.Move SE 30X Update to Firmware 9.1.46.Studio 4K 12XUpdate to Firmware 8.3.32Studio 4K 20XUpdate to Firmware 8.3.32.Studio SE 12XUpdate to Firmware 8.3.32.Studio SE 20XUpdate to Firmware 8.3.32"}],"source":{"discovery":"EXTERNAL"},"title":"PTZOptics Missing Authentication in Firmware Upload","workarounds":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<ul><li>Disable network services until the firmware can be updated.</li><li>Restrict access to the camera to a trusted management VLAN.</li></ul>"}],"value":"*  Disable network services until the firmware can be updated.\n  *  Restrict access to the camera to a trusted management VLAN."}],"x_generator":{"engine":"Vulnogram 1.0.4"}}},"cveMetadata":{"assignerOrgId":"16cac6a8-cc1e-4741-89aa-6b97e2437706","assignerShortName":"hsi","cveId":"CVE-2026-75969","datePublished":"2026-09-30T16:27:51.490Z","dateReserved":"2026-08-18T17:26:08.229Z","dateUpdated":"2026-09-30T20:01:02.432Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-30 17:16:49","lastModifiedDate":"2026-09-30 21:17:13","problem_types":["CWE-306","CWE-306 CWE-306 Missing authentication for critical function"],"metrics":{"cvssMetricV40":[{"source":"16cac6a8-cc1e-4741-89aa-6b97e2437706","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:U/V:C/RE:L/U:Red","baseScore":9.1,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"HIGH","subIntegrityImpact":"HIGH","subAvailabilityImpact":"HIGH","exploitMaturity":"UNREPORTED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"USER","valueDensity":"CONCENTRATED","vulnerabilityResponseEffort":"LOW","providerUrgency":"RED"}}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-30T18:30:11.739848Z","id":"CVE-2026-75969","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"75969","Ordinal":"1","Title":"PTZOptics Missing Authentication in Firmware Upload","CVE":"CVE-2026-75969","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"75969","Ordinal":"1","NoteData":"Missing authentication for critical function vulnerability for all PTZOptics cameras and the Firmware Upgrade Tool - Firmware Update modules. A missing authentication vulnerability in the firmware update mechanism of affected PTZOptics cameras allows an unauthenticated user to install modified firmware on the device without administrator credentials.\n\n\n\nThis vulnerability allows attackers to upload modified firmware to the device without admin credentials. This issue affects:\n\n\n\n\n\n  *  Move 4K 12X before: 0.0.98\n  *  Move 4K 20X before: 0.1.33\n  *  Move 4K 30X before: 2.1.17\n  *  Link 4K 12X before: 0.0.99\n  *  Link 4K 20X before: 0.1.37\n  *  Link 4K 30X before: 2.1.18\n  *  Move SE 12X before: 9.1.66\n  *  Move SE 20X before: 9.1.44\n  *  Move SE 30X before: 9.1.46\n  *  Studio 4K 12X before: 8.3.32\n  *  Studio 4K 20X before: 8.3.32\n  *  Studio SE 12X before: 8.3.32\n  *  Studio SE 20X before: 8.3.32\n  *  All Generation 2 cameras, including: PT12X-SDI-GY-G2, PT12X-SDI-WH-G2, PT12X-NDI-GY-G2, PT12X-NDI-WH-G2; PT12X-USB-GY-G2, PT12X-USB-WH-G2; PT20X-SDI-GY-G2, PT20X-SDI-WH-G2, PT20X-NDI-GY-G2, PT20X-NDI-WH-G2; PT20X-USB-GY-G2, PT20X-USB-WH-G2; PT30X-SDI-GY-G2, PT30X-SDI-WH-G2, PT30X-NDI-GY-G2, PT30X-NDI-WH-G2; PTVL-ZCAM, PTVL-NDI-ZCAM; PTEPTZ-ZCAM-G2, PTEPTZ-NDI-ZCAM-G2; PT12X-ZCAM, PT12X-NDI-ZCAM; PT20X-ZCAM, PT20X-NDI-ZCAM; Studio Pro - All versions\n  *  Upgrade Tool - All versions","Type":"Description","Title":"PTZOptics Missing Authentication in Firmware Upload"}]}}}