CVE-2025-30109

In the IROAD APK 5.2.5, there are Hardcoded Credentials in the APK for ports 9091 and 9092. The mobile application for the dashcam contains hardcoded credentials that allow an attacker on the local Wi-Fi network to access API endpoints and retrieve sensitive device information, including live and recorded footage.
Configurations

No configuration.

History

21 Mar 2025, 17:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
Summary
  • (es) En IROAD APK 5.2.5, hay credenciales codificadas en el APK para los puertos 9091 y 9092. La aplicación móvil para la dashcam contiene credenciales codificadas que permiten a un atacante en la red Wi-Fi local acceder a los puntos finales de la API y recuperar información confidencial del dispositivo, incluidas imágenes en vivo y grabadas.
CWE CWE-798

18 Mar 2025, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-18 15:16

Updated : 2025-03-21 17:15


NVD link : CVE-2025-30109

Mitre link : CVE-2025-30109

CVE.ORG link : CVE-2025-30109


JSON object : View

Products Affected

No product.

CWE
CWE-798

Use of Hard-coded Credentials