CVE-2026-75969 PUBLISHED

PTZOptics Missing Authentication in Firmware Upload

Assigner: hsi
Reserved: 18.08.2026 Published: 30.09.2026 Updated: 30.09.2026

Missing authentication for critical function vulnerability for all PTZOptics cameras and the Firmware Upgrade Tool - Firmware Update modules. A missing authentication vulnerability in the firmware update mechanism of affected PTZOptics cameras allows an unauthenticated user to install modified firmware on the device without administrator credentials.

This vulnerability allows attackers to upload modified firmware to the device without admin credentials. This issue affects:

  • Move 4K 12X before: 0.0.98
  • Move 4K 20X before: 0.1.33
  • Move 4K 30X before: 2.1.17
  • Link 4K 12X before: 0.0.99
  • Link 4K 20X before: 0.1.37
  • Link 4K 30X before: 2.1.18
  • Move SE 12X before: 9.1.66
  • Move SE 20X before: 9.1.44
  • Move SE 30X before: 9.1.46
  • Studio 4K 12X before: 8.3.32
  • Studio 4K 20X before: 8.3.32
  • Studio SE 12X before: 8.3.32
  • Studio SE 20X before: 8.3.32
  • All Generation 2 cameras, including: PT12X-SDI-GY-G2, PT12X-SDI-WH-G2, PT12X-NDI-GY-G2, PT12X-NDI-WH-G2; PT12X-USB-GY-G2, PT12X-USB-WH-G2; PT20X-SDI-GY-G2, PT20X-SDI-WH-G2, PT20X-NDI-GY-G2, PT20X-NDI-WH-G2; PT20X-USB-GY-G2, PT20X-USB-WH-G2; PT30X-SDI-GY-G2, PT30X-SDI-WH-G2, PT30X-NDI-GY-G2, PT30X-NDI-WH-G2; PTVL-ZCAM, PTVL-NDI-ZCAM; PTEPTZ-ZCAM-G2, PTEPTZ-NDI-ZCAM-G2; PT12X-ZCAM, PT12X-NDI-ZCAM; PT20X-ZCAM, PT20X-NDI-ZCAM; Studio Pro - All versions
  • Upgrade Tool - All versions

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U/R:U/V:C/RE:L/U:Red
CVSS Score: 9.1

Product Status

Vendor PTZOptics
Product Move 4K 12X
Versions Default: unaffected
  • affected from 0 to 0.0.98 (excl.)
Vendor PTZOptics
Product Move 4K 20X
Versions Default: unaffected
  • affected from 0 to 0.1.33 (excl.)
Vendor PTZOptics
Product Move 4K 30X
Versions Default: unaffected
  • affected from 0 to 2.1.17 (excl.)
Vendor PTZOptics
Product Link 4K 12X
Versions Default: unaffected
  • affected from 0 to 0.0.99 (excl.)
Vendor PTZOptics
Product Link 4K 20X
Versions Default: unaffected
  • affected from 0 to 0.1.37 (excl.)
Vendor PTZOptics
Product Link 4K 30X
Versions Default: unaffected
  • affected from 0 to 2.1.18 (excl.)
Vendor PTZOptics
Product Move SE 12X
Versions Default: unaffected
  • affected from 0 to 9.1.66 (excl.)
Vendor PTZOptics
Product Move SE 20X
Versions Default: unaffected
  • affected from 0 to 9.1.44 (excl.)
Vendor PTZOptics
Product Move SE 30X
Versions Default: unaffected
  • affected from 0 to 9.1.46 (excl.)
Vendor PTZOptics
Product Studio 4K 12X
Versions Default: unaffected
  • affected from 0 to 8.3.32 (excl.)
Vendor PTZOptics
Product Studio 4K 20X
Versions Default: unaffected
  • affected from 0 to 8.3.32 (excl.)
Vendor PTZOptics
Product Studio SE 12X
Versions Default: unaffected
  • affected from 0 to 8.3.32 (excl.)
Vendor PTZOptics
Product Studio SE 20X
Versions Default: unaffected
  • affected from 0 to 8.3.32 (excl.)
Vendor PTZOptics
Product PT12X-SDI-GY-G2, PT12X-SDI-WH-G2, PT12X-NDI-GY-G2, PT12X-NDI-WH-G2
Versions Default: affected
  • Version 0 is affected
Vendor PTZOptics
Product PT12X-USB-GY-G2, PT12X-USB-WH-G2
Versions Default: affected
  • Version 0 is affected
Vendor PTZOptics
Product PT20X-SDI-GY-G2, PT20X-SDI-WH-G2, PT20X-NDI-GY-G2, PT20X-NDI-WH-G2
Versions Default: affected
  • Version 0 is affected
Vendor PTZOptics
Product PT20X-USB-GY-G2, PT20X-USB-WH-G2
Versions Default: affected
  • Version 0 is affected
Vendor PTZOptics
Product PT30X-SDI-GY-G2, PT30X-SDI-WH-G2, PT30X-NDI-GY-G2, PT30X-NDI-WH-G2
Versions Default: affected
  • Version 0 is affected
Vendor PTZOptics
Product PTVL-ZCAM, PTVL-NDI-ZCAM
Versions Default: affected
  • Version 0 is affected
Vendor PTZOptics
Product PTEPTZ-ZCAM-G2, PTEPTZ-NDI-ZCAM-G2
Versions Default: affected
  • Version 0 is affected
Vendor PTZOptics
Product PT12X-ZCAM, PT12X-NDI-ZCAM
Versions Default: affected
  • Version 0 is affected
Vendor PTZOptics
Product PT20X-ZCAM, PT20X-NDI-ZCAM
Versions Default: affected
  • Version 0 is affected
Vendor PTZOptics
Product Studio Pro
Versions Default: affected
  • Version 0 is affected
Vendor PTZOptics
Product Upgrade Tool
Versions Default: affected
  • Version 0 is affected

Workarounds

  • Disable network services until the firmware can be updated.
  • Restrict access to the camera to a trusted management VLAN.

Solutions

ProductRemediationMove 4K 12XUpdate to Firmware 0.0.98.Move 4K 20XUpdate to Firmware 0.1.33.Move 4K 30XUpdate to Firmware 2.1.17.Link 4K 12XUpdate to Firmware 0.0.99.Link 4K 20XUpdate to Firmware 0.1.37.Link 4K 30XUpdate to Firmware 2.1.18.Move SE 12X Update to Firmware 9.1.66.Move SE 20X Update to Firmware 9.1.44.Move SE 30X Update to Firmware 9.1.46.Studio 4K 12XUpdate to Firmware 8.3.32Studio 4K 20XUpdate to Firmware 8.3.32.Studio SE 12XUpdate to Firmware 8.3.32.Studio SE 20XUpdate to Firmware 8.3.32

Credits

  • Haverford Systems Inc. & PTZOptics would like to thank Jaroslav Svoboda of CESNET for responsibly reporting this vulnerability. finder

References

Problem Types

  • CWE-306 Missing authentication for critical function CWE

Impacts

  • CAPEC-638 Altered Component Firmware
  • CAPEC-669 Alteration of a Software Update