Loading HuntDB...

GHSA-58rw-8pf6-2mgq

GitHub Security Advisory

⚠ Unreviewed CRITICAL Has CVE

Advisory Details

PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an insufficient authentication issue. The camera does not properly enforce authentication to /cgi-bin/param.cgi when requests are sent without an HTTP Authorization header. The result is a remote and unauthenticated attacker can leak sensitive data such as usernames, password hashes, and configurations details. Additionally, the attacker can update individual configuration values or overwrite the whole file.

Related CVEs

Key Information

GHSA ID
GHSA-58rw-8pf6-2mgq
Published
September 17, 2024 9:30 PM
Last Modified
September 17, 2024 9:30 PM
CVSS Score
9.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: June 18, 2025 6:25 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.