Executive brief
PTZOptics PT30X-SDI/NDI cameras fail to enforce authentication for the /cgi-bin/param.cgi script when an HTTP Authorization header is missing. This allows a remote, unauthenticated attacker to leak sensitive data including credentials and configuration details, or modify the device configuration.
Affected products
- PTZOptics PT30X-SDI Firmware before 6.3.40
- PTZOptics PT30X-NDI-XX-G2 Firmware before 6.3.40
Timeline
- 2024-09-17: disclosed: NVD Published Date
- 2024-11-04: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2024-11-04: exploited: Reported as exploited in the wild in advisory summary