An issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Hardcoded Credentials exist in the APK for Ports 9091 and 9092. The dashcam's Android application contains hardcoded credentials that allow unauthorized access to device settings through ports 9091 and 9092. These credentials, stored in cleartext, can be exploited by an attacker who gains access to the dashcam's network.
History

Thu, 22 May 2025 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Hella
Hella dr 820
Hella dr 820 Firmware
CPEs cpe:2.3:h:hella:dr_820:-:*:*:*:*:*:*:*
cpe:2.3:o:hella:dr_820_firmware:-:*:*:*:*:*:*:*
Vendors & Products Hella
Hella dr 820
Hella dr 820 Firmware

Fri, 21 Mar 2025 14:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-798
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 18 Mar 2025 14:45:00 +0000

Type Values Removed Values Added
Description An issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Hardcoded Credentials exist in the APK for Ports 9091 and 9092. The dashcam's Android application contains hardcoded credentials that allow unauthorized access to device settings through ports 9091 and 9092. These credentials, stored in cleartext, can be exploited by an attacker who gains access to the dashcam's network.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-03-21T13:53:45.923Z

Reserved: 2025-03-17T00:00:00.000Z

Link: CVE-2025-30113

cve-icon Vulnrichment

Updated: 2025-03-21T13:53:40.828Z

cve-icon NVD

Status : Analyzed

Published: 2025-03-18T15:16:02.453

Modified: 2025-05-22T19:51:06.857

Link: CVE-2025-30113

cve-icon Redhat

No data.