← Vulnerability feed

Vulnerability record · CVE-2024-8956 · published 17 September 2024

CVE-2024-8956: PTZOptics PT30X cameras authentication bypass via param.cgi

Ptzoptics · Pt30x Sdi Firmware

PTZOptics PT30X-SDI/NDI-xx cameras before firmware 6.3.40 fail to enforce authentication on /cgi-bin/param.cgi when a request omits the HTTP Authorization header. An unauthenticated remote attacker can read sensitive data including usernames, password hashes and configuration details, and can modify individual configuration values or overwrite the entire configuration file. The flaw is a missing/improper authentication issue on a critical function, rated CVSS 9.1 critical.

9.1 CVSS 3.1 Critical CISA KEV since 4 Nov 2024 EPSS 59% · top 0.9% CWE-306 · Missing authentication for critical functionCWE-287 · Improper authentication
9.1CVSS 3.1 base score
59%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
5References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an insufficient authentication issue. The camera does not properly enforce authentication to /cgi-bin/param.cgi when requests are sent without an HTTP Authorization header. The result is a remote and unauthenticated attacker can leak sensitive data such as usernames, password hashes, and configurations details. Additionally, the attacker can update individual configuration values or overwrite the whole file.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 9.1 with unauthenticated remote read/write access, active KEV listing and high EPSS probability make this an urgent exposure.

What it is

PTZOptics PT30X-SDI/NDI-xx cameras before firmware 6.3.40 fail to enforce authentication on /cgi-bin/param.cgi when a request omits the HTTP Authorization header. An unauthenticated remote attacker can read sensitive data including usernames, password hashes and configuration details, and can modify individual configuration values or overwrite the entire configuration file. The flaw is a missing/improper authentication issue on a critical function, rated CVSS 9.1 critical.

Impact

An attacker gains read access to credentials and configuration data and write access to camera configuration, enabling full compromise of device settings and potential reuse of leaked credentials elsewhere.

Attack surface

Reachable over the network via HTTP requests to /cgi-bin/param.cgi; no authentication is required and no user interaction is needed, as reflected by the CVSS vector AV:N/AC:L/PR:N/UI:N.

Exploitation

Listed in CISA KEV with a due date of 2024-11-25, and EPSS shows a 30-day probability of 0.61279 (99th percentile); a reference is tagged Exploit, indicating public exploit material exists. No ransomware campaign use is documented.

What to do

  • Upgrade affected PT30X-SDI/NDI-xx cameras to firmware 6.3.40 or later, or discontinue use if patching is not possible per CISA guidance.
  • Isolate cameras on a dedicated VLAN with no internet exposure and restrict management access to trusted hosts.
  • Block or filter external access to /cgi-bin/param.cgi at the network boundary until patched.
  • Rotate any credentials, password hashes or configuration secrets that may have been exposed through the flaw.
  • Monitor vendor changelog and CISA KEV for updated guidance.

Detection

  • Review web server or proxy logs for unauthenticated requests to /cgi-bin/param.cgi, especially those lacking an Authorization header.
  • Alert on configuration changes or full configuration file overwrites on PTZOptics cameras outside approved maintenance windows.
  • Hunt for scanning or enumeration activity targeting camera management interfaces on exposed networks.
  • Correlate camera management endpoint access with known internal management hosts to flag unexpected sources.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2024-8956 to the Known Exploited Vulnerabilities catalog on 4 November 2024 as "PTZOptics PT30X-SDI/NDI Cameras Authentication Bypass Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 25 November 2024.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-8956 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.2CVE-2024-8957PTZOptics PT30X cameras OS command injection via ntp_addrPTZOptics PT30X-SDI/NDI-xx cameras before firmware 6.3.40 fail to validate the ntp_addr configuration value, allowing OS command injection when ntp_c…KEVEPSS 80%analysed8.8CVE-2026-67277MikroTik RouterOS btest missing authentication leaks kernel memory and crashes kernelRouterOS accepts a "related" btest connection before the primary session is authenticated, letting an unauthenticated client start an IPv4 UDP test. …KEVEPSS 1.6%analysed8.8CVE-2026-59822LiteLLM MCP endpoint auth bypass via OAuth2 passthrough fallbackLiteLLM's MCP Streamable HTTP endpoint, prior to 1.84.0, let an unauthenticated attacker send a fabricated Authorization header that triggered an OAu…KEVEPSS 0.84%analysed9.3CVE-2026-72529TrueConf Server missing authentication allows remote script executionTrueConf Server versions 5.3.X through 5.3.9, 5.4.X through 5.4.9, 5.5.X through 5.5.5, and earlier expose an undocumented function on port 4307/TCP …KEVEPSS 1.5%analysed9.8CVE-2026-46817Oracle E-Business Suite Payments missing authentication allows takeoverOracle Payments in Oracle E-Business Suite 12.2.3 through 12.2.15 contains an easily exploitable flaw in the File Transmission component. An unauthen…KEVEPSS 0.81%analysed9.8CVE-2026-56164Microsoft SharePoint Server missing authentication allows privilege elevationMicrosoft Office SharePoint Server contains a missing authentication flaw in a critical function (CWE-306), letting an unauthenticated attacker reach…KEVEPSS 1.0%analysed9.8CVE-2026-20253Splunk Enterprise PostgreSQL sidecar missing authentication allows file writesSplunk Enterprise 10.2 below 10.2.4 and 10.x below 10.0.7 expose a PostgreSQL sidecar service endpoint that lacks authentication controls. Any networ…KEVEPSS 97%analysed9.8CVE-2026-35273Oracle PeopleSoft PeopleTools missing authentication allows takeoverOracle PeopleSoft Enterprise PeopleTools (Updates Environment Management component) in versions 8.61 and 8.62 is missing authentication for a critica…KEVEPSS 9.4%analysed

Source: NIST National Vulnerability Database (record CVE-2024-8956), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.