CVE-2025-30106

Severity CVSS v4.0:
Pending analysis
Type:
CWE-259 Use of Hard-coded Password
Publication date:
18/03/2025
Last modified:
21/03/2025

Description

On IROAD v9 devices, the dashcam has hardcoded default credentials ("qwertyuiop") that cannot be changed by the user. This allows an attacker within Wi-Fi range to connect to the device's network to perform sniffing.