CVE Feed

    Dashboard / CVE / CVE-2025-30140

    CVE-2025-30140

    An issue was discovered on G-Net Dashcam BB GONX devices. A Public Domain name is Used for the Internal Domain Name. It uses an unregistered public domain name as an internal domain, creating a security risk. This domain was not owned by GNET originally, allowing an attacker to register it and potentially intercept sensitive device traffic (it has since been registered by the vulnerability discoverer). If the dashcam or related services attempt to resolve this domain over the public Internet instead of locally, it could lead to data exfiltration or man-in-the-middle attacks.

    Published:Mar 18, 2025
    Last Modified:Jul 1, 2025
    EPS:Mar 18, 2025
    EPSS Score:0.0005
    CVSS Score:7.5

    Affected Products

    Vendor
    Gnetsystem
    Product
    G-onx
    Vendor
    Gnetsystem
    Product
    G-onx Firmware

    Exploits

    No exploit reference

    Common Weakness Enumeration

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High