PT-2025-11402 · Iroad · Iroad Dash Cam Fx2
Published
2025-03-16
·
Updated
2025-11-04
·
CVE-2025-2347
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
IROAD Dash Cam FX2 up to 20250308
Description:
A vulnerability was found in the Device Registration component of the affected software. The issue allows for the use of a default password when the
Password argument is manipulated with a specific input, such as qwertyuiop. This attack can be performed within a local network.Recommendations:
For IROAD Dash Cam FX2 up to 20250308, consider changing the default password to a strong and unique one to prevent exploitation.
As a temporary workaround, restrict access to the Device Registration component to minimize the risk of exploitation.
Avoid using default or weak passwords for the
Password argument in the affected component until the issue is resolved.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Iroad Dash Cam Fx2