PT-2025-31107 · Iroad · Iroad Dash Cam Fx2

Published

2025-07-28

·

Updated

2025-11-06

·

CVE-2025-30133

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IROAD Dashcam FX2 (affected versions not specified)
Description An issue exists in IROAD Dashcam FX2 devices that allows bypassing the device pairing and registration process. The device requires registration through the "IROAD X View" application for authentication, but the HTTP server does not enforce this restriction. An attacker connecting to the dashcam's Wi-Fi network using the default password (qwertyuiop) can directly access the HTTP server at the API endpoint http://192.168.10.1 without completing the pairing process. The device does not generate any alerts when an unauthorized connection occurs, resulting in a silent intrusion.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2025-30133

Affected Products

Iroad Dash Cam Fx2