PT-2024-7569 · Ptzoptics · Ptzoptics Pt30X-Sdi/Ndi-Xx

Konstantin Lazarev

·

Published

2024-09-17

·

Updated

2025-09-26

·

CVE-2024-8956

CVSS v3.1

9.4

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions PTZOptics PT30X-SDI/NDI-xx versions prior to 6.3.40
Description The issue is related to insufficient authentication in PTZOptics cameras. When requests are sent without an HTTP Authorization header to the /cgi-bin/param.cgi endpoint, the camera does not properly enforce authentication. This allows a remote and unauthenticated attacker to leak sensitive data, such as usernames, password hashes, and configuration details. Additionally, the attacker can update individual configuration values or overwrite the whole file. The vulnerability is being actively exploited by hackers, targeting PTZOptics cameras used in critical sectors, including healthcare, government, and industrial settings.
Recommendations For PTZOptics PT30X-SDI/NDI-xx versions prior to 6.3.40, update the firmware to version 6.3.40 or later to resolve the issue. As a temporary workaround, consider restricting access to the /cgi-bin/param.cgi endpoint to minimize the risk of exploitation. Avoid using the camera until the firmware is updated to prevent potential data leaks and configuration manipulation.

Exploit

Fix

Missing Authentication

Improper Authentication

Weakness Enumeration

Related Identifiers

BDU:2024-08975
CVE-2024-8956

Affected Products

Ptzoptics Pt30X-Sdi/Ndi-Xx