CVE-2025-35451

PTZOptics and possibly other ValueHD-based pan-tilt-zoom cameras use hard-coded, default administrative credentials. The passwords can readily be cracked. Many cameras have SSH or telnet listening on all interfaces. The passwords cannot be changed by the user, nor can the SSH or telnet service be disabled by the user.
Configurations

No configuration.

History

05 Sep 2025, 19:15

Type Values Removed Values Added
References
  • () https://www.greynoise.io/blog/greynoise-intelligence-discovers-zero-day-vulnerabilities-in-live-streaming-cameras-with-the-help-of-ai -
  • () https://www.labs.greynoise.io/grimoire/2024-10-31-sift-0-day-rce/ -

05 Sep 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-05 18:15

Updated : 2025-09-08 16:25


NVD link : CVE-2025-35451

Mitre link : CVE-2025-35451

CVE.ORG link : CVE-2025-35451


JSON object : View

Products Affected

No product.

CWE
CWE-798

Use of Hard-coded Credentials