CVE-2025-30111
Severity CVSS v4.0:
Pending analysis
Type:
CWE-306
Missing Authentication for Critical Function
Publication date:
18/03/2025
Last modified:
24/03/2025
Description
On IROAD v9 devices, one can Remotely Dump Video Footage and the Live Video Stream. The dashcam exposes endpoints that allow unauthorized users, who gained access through other means, to list and download recorded videos, as well as access live video streams without proper authentication.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH



