CVE-2025-30112

On 70mai Dash Cam 1S devices, by connecting directly to the dashcam's network and accessing the API on port 80 and RTSP on port 554, an attacker can bypass the device authorization mechanism from the official mobile app that requires a user to physically press on the power button during a connection.
Configurations

No configuration.

History

No history.

Information

Published : 2025-03-24 17:15

Updated : 2025-03-27 16:45


NVD link : CVE-2025-30112

Mitre link : CVE-2025-30112

CVE.ORG link : CVE-2025-30112


JSON object : View

Products Affected

No product.

CWE
CWE-288

Authentication Bypass Using an Alternate Path or Channel