PT-2025-10448 · Thinkware · Thinkware Car Dashcam F800 Pro

Geo-Chen

+1

·

Published

2025-03-08

·

Updated

2025-07-22

·

CVE-2025-2120

CVSS v3.1

4.6

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Thinkware Car Dashcam F800 Pro up to 20250226
Description A vulnerability was found in the Thinkware Car Dashcam F800 Pro, affecting some unknown processing of the file /tmp/hostapd.conf of the component Configuration File Handler. The manipulation leads to cleartext storage in a file or on disk. It is possible to launch the attack on the physical device. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. This issue poses significant security risks to users, including the exposure of sensitive Wi-Fi and cloud account credentials. Millions of devices worldwide may be affected.
Recommendations As a temporary workaround, consider restricting access to the Configuration File Handler component until a patch is available. Avoid using the default factory passwords, and ensure that all passwords are changed to unique and strong credentials. Restrict access to the dashcam's RTSP feed to minimize the risk of unauthorized surveillance. There is no information about a newer version that contains a fix for this vulnerability.

Exploit

Cleartext Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2025-2120

Affected Products

Thinkware Car Dashcam F800 Pro