Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-30133

Опубликовано: 28 июл. 2025
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

An issue was discovered on IROAD Dashcam FX2 devices. Bypass of Device Pairing/Registration can occur. It requires device registration via the "IROAD X View" app for authentication, but its HTTP server lacks this restriction. Once connected to the dashcam's Wi-Fi network via the default password ("qwertyuiop"), an attacker can directly access the HTTP server at http://192.168.10.1 without undergoing the pairing process. Additionally, no alert is triggered on the device when an attacker connects, making this intrusion completely silent.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:iroadau:fx2_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:iroadau:fx2:-:*:*:*:*:*:*:*

EPSS

Процентиль: 29%
0.00105
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 9.8
github
6 месяцев назад

An issue was discovered on IROAD Dashcam FX2 devices. Bypass of Device Pairing/Registration can occur. It requires device registration via the "IROAD X View" app for authentication, but its HTTP server lacks this restriction. Once connected to the dashcam's Wi-Fi network via the default password ("qwertyuiop"), an attacker can directly access the HTTP server at http://192.168.10.1 without undergoing the pairing process. Additionally, no alert is triggered on the device when an attacker connects, making this intrusion completely silent.

EPSS

Процентиль: 29%
0.00105
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-284