CVE-2026-75969
Deferred Deferred - Pending Action

Missing Authentication in PTZOptics Cameras Firmware Update

Vulnerability report for CVE-2026-75969, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: 16cac6a8-cc1e-4741-89aa-6b97e2437706

Description

Missing authentication for critical function vulnerability for all PTZOptics cameras and the Firmware Upgrade Tool - Firmware Update modules. A missing authentication vulnerability in the firmware update mechanism of affected PTZOptics cameras allows an unauthenticated user to install modified firmware on the device without administrator credentials. This vulnerability allows attackers to upload modified firmware to the device without admin credentials. This issue affects: * Move 4K 12X before: 0.0.98 * Move 4K 20X before: 0.1.33 * Move 4K 30X before: 2.1.17 * Link 4K 12X before: 0.0.99 * Link 4K 20X before: 0.1.37 * Link 4K 30X before: 2.1.18 * Move SE 12X before: 9.1.66 * Move SE 20X before: 9.1.44 * Move SE 30X before: 9.1.46 * Studio 4K 12X before: 8.3.32 * Studio 4K 20X before: 8.3.32 * Studio SE 12X before: 8.3.32 * Studio SE 20X before: 8.3.32 * All Generation 2 cameras, including: PT12X-SDI-GY-G2, PT12X-SDI-WH-G2, PT12X-NDI-GY-G2, PT12X-NDI-WH-G2; PT12X-USB-GY-G2, PT12X-USB-WH-G2; PT20X-SDI-GY-G2, PT20X-SDI-WH-G2, PT20X-NDI-GY-G2, PT20X-NDI-WH-G2; PT20X-USB-GY-G2, PT20X-USB-WH-G2; PT30X-SDI-GY-G2, PT30X-SDI-WH-G2, PT30X-NDI-GY-G2, PT30X-NDI-WH-G2; PTVL-ZCAM, PTVL-NDI-ZCAM; PTEPTZ-ZCAM-G2, PTEPTZ-NDI-ZCAM-G2; PT12X-ZCAM, PT12X-NDI-ZCAM; PT20X-ZCAM, PT20X-NDI-ZCAM; Studio Pro - All versions * Upgrade Tool - All versions

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 15 associated CPEs
Vendor Product Version / Range
ptzoptics move_4k_12x to 0.0.98 (exc)
ptzoptics move_4k_20x to 0.1.33 (exc)
ptzoptics move_4k_30x to 2.1.17 (exc)
ptzoptics link_4k_12x to 0.0.99 (exc)
ptzoptics link_4k_20x to 0.1.37 (exc)
ptzoptics link_4k_30x to 2.1.18 (exc)
ptzoptics move_se_12x to 9.1.66 (exc)
ptzoptics move_se_20x to 9.1.44 (exc)
ptzoptics move_se_30x to 9.1.46 (exc)
ptzoptics studio_4k_12x to 8.3.32 (exc)
ptzoptics studio_4k_20x to 8.3.32 (exc)
ptzoptics studio_se_12x to 8.3.32 (exc)
ptzoptics studio_se_20x to 8.3.32 (exc)
ptzoptics all_generation_2_cameras *
ptzoptics upgrade_tool *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a missing authentication for critical function issue affecting PTZOptics cameras and the Firmware Upgrade Tool. It allows unauthenticated users to upload modified firmware to devices without administrator credentials, potentially compromising device integrity and security.

Impact Analysis

Attackers could exploit this to install malicious firmware, gaining unauthorized control over cameras, accessing sensitive data, or using devices as entry points into broader networks. Affected devices include multiple PTZOptics camera models and the Firmware Upgrade Tool.

Mitigation Strategies

Update all affected PTZOptics cameras and the Firmware Upgrade Tool to the latest firmware versions listed in the CVE description. Ensure no unauthorized firmware updates are permitted without authentication.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-75969. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart