PT-2025-11613 · Forvia Hella · Hella Driving Recorder Dr 820
Published
2025-03-18
·
Updated
2025-03-21
·
CVE-2025-30113
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Forvia Hella HELLA Driving Recorder DR 820 (affected versions not specified)
Description
An issue exists where hardcoded credentials are present in the APK for ports 9091 and 9092. The dashcam's Android application contains these credentials, allowing unauthorized access to device settings through the mentioned ports. These credentials, stored in cleartext, can be exploited by an attacker who gains access to the dashcam's network.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hella Driving Recorder Dr 820