CVE-2023-43271

CRITICAL

70mai a500s <1.2.119 - Info Disclosure

Title source: llm
STIX 2.1

Description

Incorrect access control in 70mai a500s v1.2.119 allows attackers to directly access and delete the video files of the driving recorder through ftp and other protocols.

Scores

CVSS v3 9.1
EPSS 0.0029
EPSS Percentile 52.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-306
Status published
Products (1)
70mai/a500s_firmware 1.2.119
Published Oct 09, 2023
Tracked Since Feb 18, 2026