PT-2024-7569 · Ptzoptics · Ptzoptics Pt30X-Sdi/Ndi-Xx
Konstantin Lazarev
·
Published
2024-09-17
·
Updated
2025-09-26
·
CVE-2024-8956
CVSS v3.1
9.4
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
PTZOptics PT30X-SDI/NDI-xx versions prior to 6.3.40
Description
The issue is related to insufficient authentication in PTZOptics cameras. When requests are sent without an HTTP Authorization header to the /cgi-bin/param.cgi endpoint, the camera does not properly enforce authentication. This allows a remote and unauthenticated attacker to leak sensitive data, such as usernames, password hashes, and configuration details. Additionally, the attacker can update individual configuration values or overwrite the whole file. The vulnerability is being actively exploited by hackers, targeting PTZOptics cameras used in critical sectors, including healthcare, government, and industrial settings.
Recommendations
For PTZOptics PT30X-SDI/NDI-xx versions prior to 6.3.40, update the firmware to version 6.3.40 or later to resolve the issue. As a temporary workaround, consider restricting access to the /cgi-bin/param.cgi endpoint to minimize the risk of exploitation. Avoid using the camera until the firmware is updated to prevent potential data leaks and configuration manipulation.
Exploit
Fix
Missing Authentication
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ptzoptics Pt30X-Sdi/Ndi-Xx