CVE Feed

    Dashboard / CVE / CVE-2025-30135

    CVE-2025-30135

    An issue was discovered on IROAD Dashcam FX2 devices. Dumping Files Over HTTP and RTSP Without Authentication can occur. It lacks authentication controls on its HTTP and RTSP interfaces, allowing attackers to retrieve sensitive files and video recordings. By connecting to http://192.168.10.1/mnt/extsd/event/, an attacker can download all stored video recordings in an unencrypted manner. Additionally, the RTSP stream on port 8554 is accessible without authentication, allowing an attacker to view live footage.

    Published:Jul 25, 2025
    Last Modified:Nov 6, 2025
    EPS:Jul 25, 2025
    EPSS Score:0.00118
    CVSS Score:9.4

    Affected Products

    Vendor
    Iroad
    Product
    Dashcam Fx2
    Vendor
    Iroadau
    Product
    Fx2
    Vendor
    Iroadau
    Product
    Fx2 Firmware

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High