Vulnerability Intelligence Report
PTZOptics NDI and SDI Cameras /cgi-bin/param.cgi Insufficient Authentication
CVE-2024-8956
PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an insufficient authentication issue. The camera does not properly enforce authentication to /cgi-bin/param.cgi when requests are sent without an HTTP Authorization header. The result is a remote and unauthenticated attacker can leak sensitive data such as usernames, password hashes, and configurations details. Additionally, the attacker can update individual configuration values or overwrite the whole file.
CISA KEV
SSVC: Active Exploitation
Automatable
CVSS Base Score
9.1
CRITICAL
Exploitability:3.9
Impact Score:5.2
EPSS Probability:60.88%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-306 ↗CWE-306 Missing Authentication for Critical Function
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| PTZOptics | PT30X-SDI | 0 < 6.3.40 (affected) |
| PTZOptics | PT30X-NDI | 0 < 6.3.40 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | VulnCheck · Bug Bounty Provider · USA |
| Reserved | 2024-09-17T19:08:47 |
| Published | 2024-09-17T19:59:27 |
| Last Updated | 2025-11-22T12:09:58 |
Community Chatter & Buzz