CVE-2025-35452
PTZOptics and possibly other ValueHD-based pan-tilt-zoom cameras use default, shared credentials for the administrative web interface.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.8
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.85%
- CWE
- CWE-798, CWE-1392
- Published
- 2025-09-05
- Last modified
- 2026-03-12
Affected products
- PTZOptics PT12X-SE-xx-G3
- PTZOptics PT12X-SE-xx-G3
- PTZOptics PT12X-LINK-4K-xx
- PTZOptics PT12X-LINK-4K-xx
- PTZOptics PT20X-SE-xx-G3
- PTZOptics PT20X-SE-xx-G3
- PTZOptics PT20X-LINK-4K-xx
- PTZOptics PT20X-LINK-4K-xx
Weakness type
Related vulnerabilities
- CVE-2026-81640 — Softish C6 Ear Camera and EarVision Android Application Use of Hard-coded Credentials
- CVE-2026-79731 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-79950 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-79740 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-79738 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-86464 — In the current development version of Eclipse aeriOS, for which no official release has yet been...
- CVE-2026-86673 — ningzichun Student Management System Database Connection database.php mysqli_connect hard-coded credentials
- CVE-2026-80170 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...