CVE-2025-30125

An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. All dashcams were shipped with the same default credentials of 12345678, which creates an insecure-by-default condition. For users who change their passwords, it's limited to 8 characters. These short passwords can be cracked in 8 hours via low-end commercial cloud resources.
Configurations

No configuration.

History

30 Jul 2025, 16:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE CWE-798
References () https://github.com/geo-chen/Marbella/blob/main/README.md#finding-1---cve-2025-30125-same-default-credentials-and-limited-password-combinations - () https://github.com/geo-chen/Marbella/blob/main/README.md#finding-1---cve-2025-30125-same-default-credentials-and-limited-password-combinations -

29 Jul 2025, 14:14

Type Values Removed Values Added
Summary
  • (es) Se detectó un problema en Marbella KR8s Dashcam FF 2.0.8 devices. Todas las cámaras de salpicadero se entregaron con las mismas credenciales predeterminadas, 12345678, lo que genera una condición de inseguridad predeterminada. Para los usuarios que cambian sus contraseñas, esta está limitada a 8 caracteres. Estas contraseñas cortas se pueden descifrar en 8 horas mediante recursos comerciales de bajo coste en la nube.

28 Jul 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-28 15:15

Updated : 2025-07-30 16:15


NVD link : CVE-2025-30125

Mitre link : CVE-2025-30125

CVE.ORG link : CVE-2025-30125


JSON object : View

Products Affected

No product.

CWE
CWE-798

Use of Hard-coded Credentials