An issue was discovered on IROAD Dashcam FX2 devices. Dumping Files Over HTTP and RTSP Without Authentication can occur. It lacks authentication controls on its HTTP and RTSP interfaces, allowing attackers to retrieve sensitive files and video recordings. By connecting to http://192.168.10.1/mnt/extsd/event/, an attacker can download all stored video recordings in an unencrypted manner. Additionally, the RTSP stream on port 8554 is accessible without authentication, allowing an attacker to view live footage.
Metrics
Affected Vendors & Products
References
History
Tue, 05 Aug 2025 12:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Iroad
Iroad dashcam Fx2 |
|
Vendors & Products |
Iroad
Iroad dashcam Fx2 |
Fri, 25 Jul 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-306 | |
Metrics |
cvssV3_1
|
Fri, 25 Jul 2025 19:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An issue was discovered on IROAD Dashcam FX2 devices. Dumping Files Over HTTP and RTSP Without Authentication can occur. It lacks authentication controls on its HTTP and RTSP interfaces, allowing attackers to retrieve sensitive files and video recordings. By connecting to http://192.168.10.1/mnt/extsd/event/, an attacker can download all stored video recordings in an unencrypted manner. Additionally, the RTSP stream on port 8554 is accessible without authentication, allowing an attacker to view live footage. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published: 2025-07-25T00:00:00.000Z
Updated: 2025-07-25T19:42:32.655Z
Reserved: 2025-03-17T00:00:00.000Z
Link: CVE-2025-30135

Updated: 2025-07-25T19:41:36.209Z

Status : Awaiting Analysis
Published: 2025-07-25T20:15:24.203
Modified: 2025-07-29T14:14:55.157
Link: CVE-2025-30135

No data.