PT-2025-11613 · Forvia Hella · Hella Driving Recorder Dr 820

Published

2025-03-18

·

Updated

2025-03-21

·

CVE-2025-30113

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Forvia Hella HELLA Driving Recorder DR 820 (affected versions not specified)
Description An issue exists where hardcoded credentials are present in the APK for ports 9091 and 9092. The dashcam's Android application contains these credentials, allowing unauthorized access to device settings through the mentioned ports. These credentials, stored in cleartext, can be exploited by an attacker who gains access to the dashcam's network.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-30113

Affected Products

Hella Driving Recorder Dr 820