PT-2025-11617 · Forvia Hella · Hella Driving Recorder Dr 820

Published

2025-03-18

·

Updated

2025-03-18

·

CVE-2025-30117

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Forvia Hella HELLA Driving Recorder DR 820 (affected versions not specified)
Description An issue was discovered that allows unauthorized parties to manage settings and obtain sensitive data, potentially sabotaging the car battery. After bypassing device pairing, an attacker can access sensitive user and vehicle information through the settings interface. Remote attackers can modify power management settings, disable recording, delete stored footage, and turn off battery protection, leading to potential denial-of-service conditions and vehicle battery drainage.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-30117

Affected Products

Hella Driving Recorder Dr 820