CVE-2025-35451 (CNNVD-202509-787)

CRITICAL
中文标题:
PTZOptics多款产品 安全漏洞
英文标题:
Pan-Tilt-Zoom cameras hard-coded default passwords with SSH and telnet enabled
CVSS分数: 9.3
发布时间: 2025-09-05 17:43:53
漏洞类型: 其他
状态: PUBLISHED
数据质量分数: 0.40
数据版本: v4
漏洞描述
中文描述:

PTZOptics PT12X-SE-xx-G3等都是美国PTZOptics公司的一款摄像机。 PTZOptics多款产品存在安全漏洞,该漏洞源于使用硬编码默认管理凭据。以下产品受到影响:PTZOptics PT20X-SE-xx-G3、PTZOptics PT12X-LINK-4K-xx和PTZOptics PT12X-SE-xx-G3。

英文描述:

PTZOptics and possibly other ValueHD-based pan-tilt-zoom cameras use hard-coded, default administrative credentials. The passwords can readily be cracked. Many cameras have SSH or telnet listening on all interfaces. The passwords cannot be changed by the user, nor can the SSH or telnet service be disabled by the user.

CWE类型:
CWE-798
标签:
(暂无数据)
受影响产品
厂商 产品 版本 版本范围 平台 CPE
PTZOptics PT12X-SE-xx-G3 - < 9.1.43 - cpe:2.3:a:ptzoptics:pt12x-se-xx-g3:*:*:*:*:*:*:*:*
PTZOptics PT12X-LINK-4K-xx - < 0.0.63 - cpe:2.3:a:ptzoptics:pt12x-link-4k-xx:*:*:*:*:*:*:*:*
PTZOptics PT20X-SE-xx-G3 - < 9.1.32 - cpe:2.3:a:ptzoptics:pt20x-se-xx-g3:*:*:*:*:*:*:*:*
PTZOptics PT20X-LINK-4K-xx - < 0.0.89 - cpe:2.3:a:ptzoptics:pt20x-link-4k-xx:*:*:*:*:*:*:*:*
PTZOptics PT-STUDIOPRO - < 9.0.41 - cpe:2.3:a:ptzoptics:pt-studiopro:*:*:*:*:*:*:*:*
PTZOptics PT30X-SE-xx-G3 - < 9.1.33 - cpe:2.3:a:ptzoptics:pt30x-se-xx-g3:*:*:*:*:*:*:*:*
PTZOptics PT30X-LINK-4K-xx - < 2.0.71 - cpe:2.3:a:ptzoptics:pt30x-link-4k-xx:*:*:*:*:*:*:*:*
PTZOptics PT12X-STUDIO-4K-xx-G3 - < 8.1.90 - cpe:2.3:a:ptzoptics:pt12x-studio-4k-xx-g3:*:*:*:*:*:*:*:*
PTZOptics PT20X-STUDIO-4K-xx-G3 - < 8.1.90 - cpe:2.3:a:ptzoptics:pt20x-studio-4k-xx-g3:*:*:*:*:*:*:*:*
PTZOptics PT12X-SDI/NDI-xx - < 6.3.70 - cpe:2.3:a:ptzoptics:pt12x-sdi_ndi-xx:*:*:*:*:*:*:*:*
PTZOptics PT12X-USB-xx - < 6.2.88 - cpe:2.3:a:ptzoptics:pt12x-usb-xx:*:*:*:*:*:*:*:*
PTZOptics PT20X-SDI/NDI-xx - < 6.3.27 - cpe:2.3:a:ptzoptics:pt20x-sdi_ndi-xx:*:*:*:*:*:*:*:*
SMTAV Pan-Tilt-Zoom Cameras * - - cpe:2.3:a:smtav:pan-tilt-zoom_cameras:*:*:*:*:*:*:*:*
PTZOptics PT30X-SDI/NDI-xx - < 6.3.43 - cpe:2.3:a:ptzoptics:pt30x-sdi_ndi-xx:*:*:*:*:*:*:*:*
multiCAM Systems Pan-Tilt-Zoom Cameras * - - cpe:2.3:a:multicam_systems:pan-tilt-zoom_cameras:*:*:*:*:*:*:*:*
PTZOptics VL Fixed Camera/NDI Fixed Camera - < 7.2.94 - cpe:2.3:a:ptzoptics:vl_fixed_camera_ndi_fixed_camera:*:*:*:*:*:*:*:*
PTZOptics 12x Fixed Camera/NDI Fixed Camera - < 7.2.85 - cpe:2.3:a:ptzoptics:12x_fixed_camera_ndi_fixed_camera:*:*:*:*:*:*:*:*
PTZOptics 20x Fixed Camera/NDI Fixed Camera - < 7.2.94 - cpe:2.3:a:ptzoptics:20x_fixed_camera_ndi_fixed_camera:*:*:*:*:*:*:*:*
PTZOptics EPTZ Fixed Camera/NDI Fixed Camera - < 8.1.89 - cpe:2.3:a:ptzoptics:eptz_fixed_camera_ndi_fixed_camera:*:*:*:*:*:*:*:*
PTZOptics HC-EPTZ-NDI - < 8.2.14 - cpe:2.3:a:ptzoptics:hc-eptz-ndi:*:*:*:*:*:*:*:*
PTZOptics PT12X-4K-xx-G3 - < 0.0.58 - cpe:2.3:a:ptzoptics:pt12x-4k-xx-g3:*:*:*:*:*:*:*:*
PTZOptics PT20X-4K-xx-G3 - < 0.0.85 - cpe:2.3:a:ptzoptics:pt20x-4k-xx-g3:*:*:*:*:*:*:*:*
PTZOptics PT20X-USB-xx - < 6.2.81 - cpe:2.3:a:ptzoptics:pt20x-usb-xx:*:*:*:*:*:*:*:*
PTZOptics PT30X-4K-xx-G3 - < 2.0.64 - cpe:2.3:a:ptzoptics:pt30x-4k-xx-g3:*:*:*:*:*:*:*:*
ValueHD Pan-Tilt-Zoom Cameras * - - cpe:2.3:a:valuehd:pan-tilt-zoom_cameras:*:*:*:*:*:*:*:*
ptzoptics pt12x-sdi-xx-g2_firmware * - - cpe:2.3:o:ptzoptics:pt12x-sdi-xx-g2_firmware:*:*:*:*:*:*:*:*
ptzoptics pt12x-ndi-xx_firmware * - - cpe:2.3:o:ptzoptics:pt12x-ndi-xx_firmware:*:*:*:*:*:*:*:*
ptzoptics pt12x-usb-xx-g2_firmware * - - cpe:2.3:o:ptzoptics:pt12x-usb-xx-g2_firmware:*:*:*:*:*:*:*:*
ptzoptics pt20x-sdi-xx-g2_firmware * - - cpe:2.3:o:ptzoptics:pt20x-sdi-xx-g2_firmware:*:*:*:*:*:*:*:*
ptzoptics pt20x-ndi-xx_firmware * - - cpe:2.3:o:ptzoptics:pt20x-ndi-xx_firmware:*:*:*:*:*:*:*:*
ptzoptics pt20x-usb-xx-g2_firmware * - - cpe:2.3:o:ptzoptics:pt20x-usb-xx-g2_firmware:*:*:*:*:*:*:*:*
ptzoptics pt30x-sdi-xx-g2_firmware * - - cpe:2.3:o:ptzoptics:pt30x-sdi-xx-g2_firmware:*:*:*:*:*:*:*:*
ptzoptics pt30x-ndi-xx_firmware * - - cpe:2.3:o:ptzoptics:pt30x-ndi-xx_firmware:*:*:*:*:*:*:*:*
ptzoptics pt12x-zcam_firmware * - - cpe:2.3:o:ptzoptics:pt12x-zcam_firmware:*:*:*:*:*:*:*:*
ptzoptics pt20x-zcam_firmware * - - cpe:2.3:o:ptzoptics:pt20x-zcam_firmware:*:*:*:*:*:*:*:*
ptzoptics ptvl-zcam_firmware * - - cpe:2.3:o:ptzoptics:ptvl-zcam_firmware:*:*:*:*:*:*:*:*
ptzoptics pteptz-zcam-g2_firmware * - - cpe:2.3:o:ptzoptics:pteptz-zcam-g2_firmware:*:*:*:*:*:*:*:*
ptzoptics pteptz-ndi-zcam-g2_firmware * - - cpe:2.3:o:ptzoptics:pteptz-ndi-zcam-g2_firmware:*:*:*:*:*:*:*:*
ptzoptics vl_fixed_camera_firmware * - - cpe:2.3:o:ptzoptics:vl_fixed_camera_firmware:*:*:*:*:*:*:*:*
ptzoptics ndi_fixed_camera_firmware * - - cpe:2.3:o:ptzoptics:ndi_fixed_camera_firmware:*:*:*:*:*:*:*:*
multicam-systems mcamii_ptz_firmware * - - cpe:2.3:o:multicam-systems:mcamii_ptz_firmware:*:*:*:*:*:*:*:*
smtav ba30s_firmware * - - cpe:2.3:o:smtav:ba30s_firmware:*:*:*:*:*:*:*:*
smtav ba20s_firmware * - - cpe:2.3:o:smtav:ba20s_firmware:*:*:*:*:*:*:*:*
smtav bv20s_firmware * - - cpe:2.3:o:smtav:bv20s_firmware:*:*:*:*:*:*:*:*
smtav bx30s_firmware * - - cpe:2.3:o:smtav:bx30s_firmware:*:*:*:*:*:*:*:*
smtav bx20n_firmware * - - cpe:2.3:o:smtav:bx20n_firmware:*:*:*:*:*:*:*:*
smtav bx20uhd-n_firmware * - - cpe:2.3:o:smtav:bx20uhd-n_firmware:*:*:*:*:*:*:*:*
smtav bx20uhd_firmware * - - cpe:2.3:o:smtav:bx20uhd_firmware:*:*:*:*:*:*:*:*
smtav ba30-n_firmware * - - cpe:2.3:o:smtav:ba30-n_firmware:*:*:*:*:*:*:*:*
smtav ba20-n_firmware * - - cpe:2.3:o:smtav:ba20-n_firmware:*:*:*:*:*:*:*:*
smtav ba12-n_firmware * - - cpe:2.3:o:smtav:ba12-n_firmware:*:*:*:*:*:*:*:*
smtav hd17h-n_firmware * - - cpe:2.3:o:smtav:hd17h-n_firmware:*:*:*:*:*:*:*:*
smtav bx20s-sh_firmware * - - cpe:2.3:o:smtav:bx20s-sh_firmware:*:*:*:*:*:*:*:*
smtav hd17h_firmware * - - cpe:2.3:o:smtav:hd17h_firmware:*:*:*:*:*:*:*:*
smtav bv30s_firmware * - - cpe:2.3:o:smtav:bv30s_firmware:*:*:*:*:*:*:*:*
smtav ba12s_firmware * - - cpe:2.3:o:smtav:ba12s_firmware:*:*:*:*:*:*:*:*
valuehd vx90_firmware * - - cpe:2.3:o:valuehd:vx90_firmware:*:*:*:*:*:*:*:*
valuehd vx720l_firmware * - - cpe:2.3:o:valuehd:vx720l_firmware:*:*:*:*:*:*:*:*
valuehd vx752ag_firmware * - - cpe:2.3:o:valuehd:vx752ag_firmware:*:*:*:*:*:*:*:*
valuehd vx752a_firmware * - - cpe:2.3:o:valuehd:vx752a_firmware:*:*:*:*:*:*:*:*
valuehd vx751ba_firmware * - - cpe:2.3:o:valuehd:vx751ba_firmware:*:*:*:*:*:*:*:*
valuehd vx630al_firmware * - - cpe:2.3:o:valuehd:vx630al_firmware:*:*:*:*:*:*:*:*
valuehd vx61asl_firmware * - - cpe:2.3:o:valuehd:vx61asl_firmware:*:*:*:*:*:*:*:*
valuehd vx61basl_firmware * - - cpe:2.3:o:valuehd:vx61basl_firmware:*:*:*:*:*:*:*:*
valuehd vx60asl_firmware * - - cpe:2.3:o:valuehd:vx60asl_firmware:*:*:*:*:*:*:*:*
valuehd vx61al_firmware * - - cpe:2.3:o:valuehd:vx61al_firmware:*:*:*:*:*:*:*:*
valuehd vx60al_firmware * - - cpe:2.3:o:valuehd:vx60al_firmware:*:*:*:*:*:*:*:*
valuehd vx701ra_firmware * - - cpe:2.3:o:valuehd:vx701ra_firmware:*:*:*:*:*:*:*:*
valuehd vx701ta_firmware * - - cpe:2.3:o:valuehd:vx701ta_firmware:*:*:*:*:*:*:*:*
valuehd vx800i2_firmware * - - cpe:2.3:o:valuehd:vx800i2_firmware:*:*:*:*:*:*:*:*
valuehd v61w_firmware * - - cpe:2.3:o:valuehd:v61w_firmware:*:*:*:*:*:*:*:*
valuehd v63xl_firmware * - - cpe:2.3:o:valuehd:v63xl_firmware:*:*:*:*:*:*:*:*
valuehd v60xl_firmware * - - cpe:2.3:o:valuehd:v60xl_firmware:*:*:*:*:*:*:*:*
valuehd vx70uvs_firmware * - - cpe:2.3:o:valuehd:vx70uvs_firmware:*:*:*:*:*:*:*:*
valuehd vx71uvs_firmware * - - cpe:2.3:o:valuehd:vx71uvs_firmware:*:*:*:*:*:*:*:*
valuehd v71uvs_firmware * - - cpe:2.3:o:valuehd:v71uvs_firmware:*:*:*:*:*:*:*:*
解决方案
中文解决方案:
(暂无数据)
英文解决方案:
(暂无数据)
临时解决方案:
(暂无数据)
参考链接
url OTHER
cve.org
访问
url OTHER
cve.org
访问
url OTHER
cve.org
访问
url OTHER
cve.org
访问
url OTHER
cve.org
访问
CVSS评分详情
3.1 (cna)
CRITICAL
9.8
CVSS向量: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
机密性
HIGH
完整性
HIGH
可用性
HIGH
4.0 (cna)
CRITICAL
9.3
CVSS向量: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
机密性
HIGH
完整性
HIGH
可用性
HIGH
后续系统影响 (Subsequent):
机密性
NONE
完整性
NONE
可用性
NONE
时间信息
发布时间:
2025-09-05 17:43:53
修改时间:
2025-09-08 18:08:29
创建时间:
2025-11-11 15:40:26
更新时间:
2026-01-15 06:00:26
利用信息
暂无可利用代码信息
数据源详情
数据源 记录ID 版本 提取时间
CVE cve_CVE-2025-35451 2025-11-11 15:23:17 2025-11-11 07:40:26
NVD nvd_CVE-2025-35451 2025-11-11 15:01:01 2025-11-11 07:48:15
CNNVD cnnvd_CNNVD-202509-787 2025-11-11 15:12:56 2025-11-11 08:00:15
版本与语言
当前版本: v4
主要语言: EN
支持语言:
ZH EN
安全公告
暂无安全公告信息
变更历史
v4 NVD
2026-01-15 06:00:26
affected_products_count: 25 → 76
查看详细变更
  • affected_products_count: 25 -> 76
v3 CNNVD
2025-11-11 16:00:15
vulnerability_type: 未提取 → 其他; cnnvd_id: 未提取 → CNNVD-202509-787; data_sources: ['cve', 'nvd'] → ['cnnvd', 'cve', 'nvd']
查看详细变更
  • vulnerability_type: 未提取 -> 其他
  • cnnvd_id: 未提取 -> CNNVD-202509-787
  • data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
v2 NVD
2025-11-11 15:48:15
data_sources: ['cve'] → ['cve', 'nvd']
查看详细变更
  • data_sources: ['cve'] -> ['cve', 'nvd']