Executive brief
PTZOptics PT30X-SDI/NDI cameras contain an OS command injection vulnerability in the ntp_addr parameter of the /cgi-bin/param.cgi script. An authenticated attacker can execute arbitrary commands with root privileges; however, when chained with CVE-2024-8956, the vulnerability can be exploited by an unauthenticated remote attacker.
Affected products
- PTZOptics PT30X-SDI Firmware before 6.3.40
- PTZOptics PT30X-NDI-XX-G2 Firmware before 6.3.40
Timeline
- 2024-09-17: disclosed: NVD Published Date
- 2024-11-04: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2024-11-04: exploited: Reported as exploited in the wild by CISA and GreyNoise