CVE-2025-35451
PTZOptics and possibly other ValueHD-based pan-tilt-zoom cameras use hard-coded, default administrative credentials. The passwords can readily be cracked. Many cameras have SSH or telnet listening on all interfaces. The passwords cannot be changed by the user, nor can the SSH or telnet service be disabled by the user.
Vendor
Product
CWE
Yayın Tarihi
2025-09-05 18:15:41
Güncelleme
2026-01-14 15:33:46
Source Identifier
9119a7d8-5eab-497f-8521-727c672e3725
KEV Date Added
-
Kategoriler
Referanslar
https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2025/icsa-25-162-10.json
https://www.cisa.gov/news-events/ics-advisories/icsa-25-162-10
https://www.cve.org/CVERecord?id=CVE-2025-35451
https://www.greynoise.io/blog/greynoise-intelligence-discovers-zero-day-vulnerabilities-in-live-streaming-cameras-with-the-help-of-ai
https://www.labs.greynoise.io/grimoire/2024-10-31-sift-0-day-rce/