PT-2025-11644 · G Net · G-Net Dashcam Bb Gonx
Published
2025-03-18
·
Updated
2025-07-02
·
CVE-2025-30141
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
G-Net Dashcam BB GONX devices (affected versions not specified)
Description
The issue allows remote access to recorded and live video feeds on the G-Net Dashcam BB GONX devices. It exposes
API endpoints on ports 9091 and 9092, enabling an attacker connected to the dashcam's network to retrieve all stored recordings and convert them from JDR format to MP4. Additionally, the RTSP stream on port 9092 can be accessed remotely, allowing real-time video feeds to be extracted without the owner's knowledge.Recommendations
As a temporary workaround, consider restricting access to the
API endpoints on ports 9091 and 9092 to minimize the risk of exploitation.
Restrict access to the RTSP stream on port 9092 to prevent real-time video feeds from being extracted without the owner's knowledge.
Avoid using the affected G-Net Dashcam BB GONX devices on unsecured networks until a fix is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
G-Net Dashcam Bb Gonx