CVE Vulnerabilities

CVE-2025-30112

Authentication Bypass Using an Alternate Path or Channel

Published: Mar 24, 2025 | Modified: Mar 24, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

On 70mai Dash Cam 1S devices, by connecting directly to the dashcams network and accessing the API on port 80 and RTSP on port 554, an attacker can bypass the device authorization mechanism from the official mobile app that requires a user to physically press on the power button during a connection.

Weakness

A product requires authentication, but the product has an alternate path or channel that does not require authentication.

Potential Mitigations

References