Hackers are attempting to exploit two zero-day vulnerabilities in PTZOptics pan-tilt-zoom (PTZ) live streaming cameras, which are often used in industries, healthcare organizations, business conferences, government and judicial settings.

In April 2024, GreyNoise discovered the vulnerabilities CVE-2024-8956 and CVE-2024-8957, after detecting unusual activity in the company's honeypot network.
Somehow, GreyNoise researchers began investigating and uncovered an exploit attempt that targeted the camera's CGI-based API and incorporated "ntp_client" with the aim of achieving command injection.
See also: WordPress: New Serious Vulnerability in LiteSpeed Cache plugin
GreyNoise researcher Konstantin Lazarevtook a closer look at the two vulnerabilities. The first, CVE-2024-8956, is related to an authentication issue in the camera's 'lighthttpd' web server, which allows unauthorized users to access the CGI API without an authorization header. As a result, information such as usernames, MD5 password hashes, and network configurations are exposed.
The second vulnerability, CVE-2024-8957, is caused by insufficient input sanitization in the 'ntp. addr' field. Attackers can use a specially crafted payload to inject commands for remote code execution.
According to Greynoise, exploiting these two vulnerabilities could allow an attacker to take full control of PTZ cameras, infect them with malware, disrupt video streams, and infiltrate other devices connected to the same network.
The company says that in addition to unusual activity in its honeypot, it also observed a distinct exploitation attempt.
Following the discovery of CVE-2024-8956 and CVE-2024-8957, GreyNoise partnered with VulnCheck to responsibly disclose them to affected vendors.
The affected devices are PTZ cameras based on Hisilicon Hi3516A V600 SoC V60, V61 and V63. They are running VHD PTZ firmware versions older than 6.3.40.
See also: QNAP fixes second zero-day vulnerability presented at Pwn2Own Ireland
PTZOptics released a security update on September 17th, but models such as the PT20X-NDI-G2 and PT12X-NDI-G2 did not receive an update due to them being no longer supported (end-of-life).

Later, GreyNoise discovered that at least two newer models, the PT20X-SE-NDI-G3 and PT30X-SE-NDI-G3, which also did not receive a patch, were affected. PTZOptics was notified on October 25th, but no fixes have been released for these models as of yet.
"We believe a wider range of devices, possibly indicating that the real culprit lies in the SDK used by the manufacturer (ValueHD/VHD Corporation)," GreyNoise told BleepingComputer.
That said, users should contact their device vendor to see if fixes for CVE-2024-8956 and CVE-2024-8957 have been incorporated into the latest available firmware update.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
This recent incident serves as a reminder that even seemingly innocuous devices like live streaming cameras can be vulnerable to cyberattacks strong. The use of internet-connected devices continues to grow across various industries, making it increasingly important to prioritize cybersecurity measures. Organizations must not only implement security protocols but also regularly update their systems with the latest updates and patches to avoid falling victim to breaches.
See also: Vulnerabilities found in open-source AI and ML models
In addition to implementing technical security measures, organizations should also focus on educating their employees about risks and best practices for staying safe online. This includes training on identifying and reporting suspicious messages and activities, creating strong passwords, and adhering to appropriate security protocols when using devices.
Additionally, it is important for manufacturers to prioritize security when designing and developing devices. With the increasing adoption of smart home devices and other IoT, manufacturers need to incorporate strong security features into their products.
Source: www.bleepingcomputer.com
