On IROAD v9 devices, one can Remotely Dump Video Footage and the Live Video Stream. The dashcam exposes endpoints that allow unauthorized users, who gained access through other means, to list and download recorded videos, as well as access live video streams without proper authentication.
References
Configurations
No configuration.
History
24 Mar 2025, 22:15
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
CWE | CWE-306 |
18 Mar 2025, 15:16
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-03-18 15:16
Updated : 2025-03-24 22:15
NVD link : CVE-2025-30111
Mitre link : CVE-2025-30111
CVE.ORG link : CVE-2025-30111
JSON object : View
Products Affected
No product.
CWE
CWE-306
Missing Authentication for Critical Function