CVE-2025-2348

MEDIUM

Iroadau Fx2 Firmware < 2025-03-08 - Information Disclosure

Title source: rule
STIX 2.1

Description

A vulnerability was found in IROAD Dash Cam FX2 up to 20250308. It has been classified as problematic. Affected is an unknown function of the file /mnt/extsd/event/ of the component HTTP/RTSP. The manipulation leads to information disclosure. The attack needs to be initiated within the local network. The exploit has been disclosed to the public and may be used.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry
https://vuldb.com/?id.299814
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.299814

Scores

CVSS v3 4.3
EPSS 0.0020
EPSS Percentile 9.9%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200 CWE-284
Status published
Products (1)
iroadau/fx2_firmware < 2025-03-08
Published Mar 16, 2025
Tracked Since Feb 18, 2026