Missing Authentication Vulnerability in PTZOptics Cameras and Firmware Upgrade Tool
CVE-2026-75969
9.1CRITICAL
What is CVE-2026-75969?
This vulnerability in PTZOptics cameras and the Firmware Upgrade Tool compromises device security by allowing unauthenticated users to upload modified firmware. This flaw arises from inadequate authentication in firmware update mechanisms, enabling unauthorized access to critical functions. Affected models span various series including Move, Link, and Studio cameras, alongside the Upgrade Tool.
Affected Version(s)
Link 4K 12X 0 < 0.0.99
Link 4K 20X 0 < 0.1.37
Link 4K 30X 0 < 2.1.18
References
CVSS V4
Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Haverford Systems Inc. & PTZOptics would like to thank Jaroslav Svoboda of CESNET for responsibly reporting this vulnerability.
