CVE-2025-30115

An issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Default Credentials Cannot Be Changed. It uses a fixed default SSID and password ("qwertyuiop"), which cannot be modified by users. The SSID is continuously broadcast, allowing unauthorized access to the device network.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:hella:dr_820_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hella:dr_820:-:*:*:*:*:*:*:*

History

22 May 2025, 19:44

Type Values Removed Values Added
References () https://github.com/geo-chen/Hella - () https://github.com/geo-chen/Hella - Third Party Advisory
References () https://medium.com/@geochen/cve-draft-hella-driving-recorder-dr-820-ff8c4e2cca26 - () https://medium.com/@geochen/cve-draft-hella-driving-recorder-dr-820-ff8c4e2cca26 - Permissions Required
First Time Hella dr 820
Hella
Hella dr 820 Firmware
CPE cpe:2.3:o:hella:dr_820_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hella:dr_820:-:*:*:*:*:*:*:*

21 Mar 2025, 14:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
Summary
  • (es) Se detectó un problema en Forvia Hella HELLA Driving Recorder DR 820. Las credenciales predeterminadas no se pueden cambiar. Utiliza un SSID y una contraseña predeterminados ("qwertyuiop"), que los usuarios no pueden modificar. El SSID se transmite continuamente, lo que permite el acceso no autorizado a la red del dispositivo.
CWE CWE-259

18 Mar 2025, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-18 15:16

Updated : 2025-05-22 19:44


NVD link : CVE-2025-30115

Mitre link : CVE-2025-30115

CVE.ORG link : CVE-2025-30115


JSON object : View

Products Affected

hella

  • dr_820
  • dr_820_firmware
CWE
CWE-259

Use of Hard-coded Password