PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-35451 PTZOptics CVE debrief

CVE-2025-35451 is a critical default-access issue affecting multiple PTZOptics camera models and related ValueHD-based camera lines listed by CISA. The advisory says SSH and/or telnet are enabled by default, administrative users including root have default passwords that are trivial to crack, and users cannot change those passwords or disable the services.

Vendor
PTZOptics
Product
PTZOptics PT12X-SDI-xx-G2
CVSS
CRITICAL 9.8
CISA KEV
Not listed in stored evidence
Original CVE published
2025-06-12
Original CVE updated
2025-06-12
Advisory published
2025-06-12
Advisory updated
2025-06-12

Who should care

Organizations that deploy PTZOptics, ValueHD, multiCAM Systems, or SMTAV pan-tilt-zoom cameras should treat this as an immediate review item, especially where cameras support remote administration or are deployed in operational or enterprise networks. Security, IT, and OT teams responsible for embedded devices and network segmentation should verify exposure and remediation status.

Technical summary

CISA’s CSAF advisory for CVE-2025-35451 describes a design-level authentication and service-hardening problem in affected cameras: SSH or telnet, or both, are enabled by default; OS administrative accounts have default passwords that are trivial to crack; and the user cannot change those passwords or disable the services. The affected product list spans multiple PTZOptics models and broader ValueHD-family camera entries, with PTZOptics providing fixes for the listed affected versions via its known vulnerabilities and fixes page.

Defensive priority

Immediate. The issue is network-reachable in nature, rated CVSS 3.1 9.8/CRITICAL by the advisory, and centers on default administrative access that cannot be user-hardened on the affected device. Prioritize asset identification, exposure reduction, and vendor-supported remediation.

Recommended defensive actions

  • Inventory all PTZOptics, ValueHD, multiCAM Systems, and SMTAV camera deployments against the affected model/version list in the CISA advisory.
  • Check whether SSH and/or telnet are enabled on each device and whether the device is reachable from untrusted or broadly shared networks.
  • Apply the vendor fix path provided by PTZOptics for the affected versions using the vendor’s known vulnerabilities and fixes page.
  • If a device cannot be remediated immediately, isolate it with network segmentation and restrict administrative access to trusted management hosts only.
  • Review operational monitoring for unexpected logins or configuration changes on camera management interfaces and adjacent network devices.
  • Follow CISA ICS recommended practices for embedded and industrial control systems while planning longer-term device replacement or upgrade where needed.

Evidence notes

All substantive claims are drawn from the supplied CISA CSAF advisory and its referenced official links. The advisory states that SSH/telnet are enabled by default, administrative users have trivial default passwords, and users cannot change the passwords or disable the services. The supplied enrichment shows the issue is not currently marked as KEV. No exploit technique, proof-of-concept, or unsupported exposure claim is included.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-35451 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-35451

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-35451 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-35451

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-162-10.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-162-10

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.