Vulnerability record · CVE-2024-8956 · published 17 September 2024
CVE-2024-8956: PTZOptics PT30X cameras authentication bypass via param.cgi
Ptzoptics · Pt30x Sdi Firmware
PTZOptics PT30X-SDI/NDI-xx cameras before firmware 6.3.40 fail to enforce authentication on /cgi-bin/param.cgi when a request omits the HTTP Authorization header. An unauthenticated remote attacker can read sensitive data including usernames, password hashes and configuration details, and can modify individual configuration values or overwrite the entire configuration file. The flaw is a missing/improper authentication issue on a critical function, rated CVSS 9.1 critical.
Description
PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an insufficient authentication issue. The camera does not properly enforce authentication to /cgi-bin/param.cgi when requests are sent without an HTTP Authorization header. The result is a remote and unauthenticated attacker can leak sensitive data such as usernames, password hashes, and configurations details. Additionally, the attacker can update individual configuration values or overwrite the whole file.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Automated analysis
critical priorityCVSS 9.1 with unauthenticated remote read/write access, active KEV listing and high EPSS probability make this an urgent exposure.
What it is
PTZOptics PT30X-SDI/NDI-xx cameras before firmware 6.3.40 fail to enforce authentication on /cgi-bin/param.cgi when a request omits the HTTP Authorization header. An unauthenticated remote attacker can read sensitive data including usernames, password hashes and configuration details, and can modify individual configuration values or overwrite the entire configuration file. The flaw is a missing/improper authentication issue on a critical function, rated CVSS 9.1 critical.
Impact
An attacker gains read access to credentials and configuration data and write access to camera configuration, enabling full compromise of device settings and potential reuse of leaked credentials elsewhere.
Attack surface
Reachable over the network via HTTP requests to /cgi-bin/param.cgi; no authentication is required and no user interaction is needed, as reflected by the CVSS vector AV:N/AC:L/PR:N/UI:N.
Exploitation
Listed in CISA KEV with a due date of 2024-11-25, and EPSS shows a 30-day probability of 0.61279 (99th percentile); a reference is tagged Exploit, indicating public exploit material exists. No ransomware campaign use is documented.
What to do
- Upgrade affected PT30X-SDI/NDI-xx cameras to firmware 6.3.40 or later, or discontinue use if patching is not possible per CISA guidance.
- Isolate cameras on a dedicated VLAN with no internet exposure and restrict management access to trusted hosts.
- Block or filter external access to /cgi-bin/param.cgi at the network boundary until patched.
- Rotate any credentials, password hashes or configuration secrets that may have been exposed through the flaw.
- Monitor vendor changelog and CISA KEV for updated guidance.
Detection
- Review web server or proxy logs for unauthenticated requests to /cgi-bin/param.cgi, especially those lacking an Authorization header.
- Alert on configuration changes or full configuration file overwrites on PTZOptics cameras outside approved maintenance windows.
- Hunt for scanning or enumeration activity targeting camera management interfaces on exposed networks.
- Correlate camera management endpoint access with known internal management hosts to flag unexpected sources.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2024-8956 to the Known Exploited Vulnerabilities catalog on 4 November 2024 as "PTZOptics PT30X-SDI/NDI Cameras Authentication Bypass Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 25 November 2024.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://ptzoptics.com/firmware-changelog/ | Release Notes |
| https://vulncheck.com/advisories/ptzoptics-insufficient-auth | Third Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-8956 | US Government Resource |
| https://www.greynoise.io/blog/greynoise-intelligence-discovers-zero-day-vulnerabilities-in-live-streaming-cameras-with-t | Third Party Advisory |
| https://www.labs.greynoise.io/grimoire/2024-10-31-sift-0-day-rce/ | ExploitThird Party Advisory |
Track CVE-2024-8956 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-8956), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.