CVE-2026-75969: PTZOptics Missing Authentication in Firmware Upload
Missing authentication for critical function vulnerability for all PTZOptics cameras and the Firmware Upgrade Tool - Firmware Update modules. A missing authentication vulnerability in the firmware update mechanism of affected PTZOptics cameras allows an unauthenticated user to install modified firmware on the device without administrator credentials.
This vulnerability allows attackers to upload modified firmware to the device without admin credentials. This issue affects:
Move 4K 12X before: 0.0.98 Move 4K 20X before: 0.1.33 Move 4K 30X before: 2.1.17 Link 4K 12X before: 0.0.99 Link 4K 20X before: 0.1.37 Link 4K 30X before: 2.1.18 Move SE 12X before: 9.1.66 Move SE 20X before: 9.1.44 Move SE 30X before: 9.1.46 Studio 4K 12X before: 8.3.32 Studio 4K 20X before: 8.3.32 Studio SE 12X before: 8.3.32 Studio SE 20X before: 8.3.32 All Generation 2 cameras, including: PT12X-SDI-GY-G2, PT12X-SDI-WH-G2, PT12X-NDI-GY-G2, PT12X-NDI-WH-G2; PT12X-USB-GY-G2, PT12X-USB-WH-G2; PT20X-SDI-GY-G2, PT20X-SDI-WH-G2, PT20X-NDI-GY-G2, PT20X-NDI-WH-G2; PT20X-USB-GY-G2, PT20X-USB-WH-G2; PT30X-SDI-GY-G2, PT30X-SDI-WH-G2, PT30X-NDI-GY-G2, PT30X-NDI-WH-G2; PTVL-ZCAM, PTVL-NDI-ZCAM; PTEPTZ-ZCAM-G2, PTEPTZ-NDI-ZCAM-G2; PT12X-ZCAM, PT12X-NDI-ZCAM; PT20X-ZCAM, PT20X-NDI-ZCAM; Studio Pro - All versions Upgrade Tool - All versions
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
PTZOptics Move 4K 12Xto a version that resolves this vulnerability.Fixed in 0.0.98 - Upgrade
Upgrade
PTZOptics Move 4K 20Xto a version that resolves this vulnerability.Fixed in 0.1.33 - Upgrade
Upgrade
PTZOptics Move 4K 30Xto a version that resolves this vulnerability.Fixed in 2.1.17 - Upgrade
Upgrade
PTZOptics Link 4K 12Xto a version that resolves this vulnerability.Fixed in 0.0.99 - Upgrade
Upgrade
PTZOptics Link 4K 20Xto a version that resolves this vulnerability.Fixed in 0.1.37 - Upgrade
Upgrade
PTZOptics Link 4K 30Xto a version that resolves this vulnerability.Fixed in 2.1.18 - Upgrade
Upgrade
PTZOptics Move SE 12Xto a version that resolves this vulnerability.Fixed in 9.1.66 - Upgrade
Upgrade
PTZOptics Move SE 20Xto a version that resolves this vulnerability.Fixed in 9.1.44 - Upgrade
Upgrade
PTZOptics Move SE 30Xto a version that resolves this vulnerability.Fixed in 9.1.46 - Upgrade
Upgrade
PTZOptics Studio 4K 12X, Studio 4K 20X, Studio SE 12X, Studio SE 20Xto a version that resolves this vulnerability.Fixed in 8.3.32
Event History
Frequently Asked Questions
Which devices can be identified as affected from the available version information?
Affected versions are below 0.0.98 for Move 4K 12X, 0.1.33 for Move 4K 20X, 2.1.17 for Move 4K 30X, 0.0.99 for Link 4K 12X, 0.1.37 for Link 4K 20X, and 2.1.18 for Link 4K 30X. Move SE, Studio 4K, Studio SE, and all Generation 2 camera models are also identified as affected, with the stated version thresholds where provided.
What level of authorization does an attacker need to install modified firmware?
The firmware update mechanism accepts modified firmware from an unauthenticated user. Administrator credentials are not required to upload the modified firmware.