PT-2025-11402 · Iroad · Iroad Dash Cam Fx2

Published

2025-03-16

·

Updated

2025-11-04

·

CVE-2025-2347

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: IROAD Dash Cam FX2 up to 20250308
Description: A vulnerability was found in the Device Registration component of the affected software. The issue allows for the use of a default password when the Password argument is manipulated with a specific input, such as qwertyuiop. This attack can be performed within a local network.
Recommendations: For IROAD Dash Cam FX2 up to 20250308, consider changing the default password to a strong and unique one to prevent exploitation. As a temporary workaround, restrict access to the Device Registration component to minimize the risk of exploitation. Avoid using default or weak passwords for the Password argument in the affected component until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-2347

Affected Products

Iroad Dash Cam Fx2