PT-2025-31107 · Iroad · Iroad Dash Cam Fx2
Published
2025-07-28
·
Updated
2025-11-06
·
CVE-2025-30133
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
IROAD Dashcam FX2 (affected versions not specified)
Description
An issue exists in IROAD Dashcam FX2 devices that allows bypassing the device pairing and registration process. The device requires registration through the "IROAD X View" application for authentication, but the HTTP server does not enforce this restriction. An attacker connecting to the dashcam's Wi-Fi network using the default password (
qwertyuiop) can directly access the HTTP server at the API endpoint http://192.168.10.1 without completing the pairing process. The device does not generate any alerts when an unauthorized connection occurs, resulting in a silent intrusion.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Iroad Dash Cam Fx2