An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. Once access is gained either by default, common, or cracked passwords, the video recordings (containing sensitive routes, conversations, and footage) are open for downloading by creating a socket to command port 7777, and then downloading video via port 7778 and audio via port 7779.
History

Wed, 06 Aug 2025 18:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284
CWE-521
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 06 Aug 2025 17:15:00 +0000

Type Values Removed Values Added
Description An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. Once access is gained either by default, common, or cracked passwords, the video recordings (containing sensitive routes, conversations, and footage) are open for downloading by creating a socket to command port 7777, and then downloading video via port 7778 and audio via port 7779.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2025-08-06T00:00:00.000Z

Updated: 2025-08-06T17:47:29.029Z

Reserved: 2025-03-17T00:00:00.000Z

Link: CVE-2025-30127

cve-icon Vulnrichment

Updated: 2025-08-06T17:42:14.626Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-08-06T17:15:38.270

Modified: 2025-08-06T20:23:37.600

Link: CVE-2025-30127

cve-icon Redhat

No data.