PT-2025-10448 · Thinkware · Thinkware Car Dashcam F800 Pro
Geo-Chen
+1
·
Published
2025-03-08
·
Updated
2025-07-22
·
CVE-2025-2120
CVSS v3.1
4.6
Medium
| Vector | AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Thinkware Car Dashcam F800 Pro up to 20250226
Description
A vulnerability was found in the Thinkware Car Dashcam F800 Pro, affecting some unknown processing of the file /tmp/hostapd.conf of the component Configuration File Handler. The manipulation leads to cleartext storage in a file or on disk. It is possible to launch the attack on the physical device. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. This issue poses significant security risks to users, including the exposure of sensitive Wi-Fi and cloud account credentials. Millions of devices worldwide may be affected.
Recommendations
As a temporary workaround, consider restricting access to the Configuration File Handler component until a patch is available. Avoid using the default factory passwords, and ensure that all passwords are changed to unique and strong credentials. Restrict access to the dashcam's RTSP feed to minimize the risk of unauthorized surveillance. There is no information about a newer version that contains a fix for this vulnerability.
Exploit
Cleartext Storage of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Thinkware Car Dashcam F800 Pro