In the IROAD APK 5.2.5, there are Hardcoded Credentials in the APK for ports 9091 and 9092. The mobile application for the dashcam contains hardcoded credentials that allow an attacker on the local Wi-Fi network to access API endpoints and retrieve sensitive device information, including live and recorded footage.
Metrics
Affected Vendors & Products
References
History
Fri, 21 Mar 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-798 | |
Metrics |
cvssV3_1
|
Tue, 18 Mar 2025 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | In the IROAD APK 5.2.5, there are Hardcoded Credentials in the APK for ports 9091 and 9092. The mobile application for the dashcam contains hardcoded credentials that allow an attacker on the local Wi-Fi network to access API endpoints and retrieve sensitive device information, including live and recorded footage. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-03-21T16:31:35.592Z
Reserved: 2025-03-17T00:00:00.000Z
Link: CVE-2025-30109

Updated: 2025-03-21T16:31:26.737Z

Status : Awaiting Analysis
Published: 2025-03-18T15:16:02.063
Modified: 2025-03-21T17:15:40.447
Link: CVE-2025-30109

No data.