CVE-2025-30112

HIGH

70mai Dash Cam 1S - Unauthenticated Authentication Bypass via Direct Network API Access

Title source: llm
STIX 2.1

Description

On 70mai Dash Cam 1S devices, by connecting directly to the dashcam's network and accessing the API on port 80 and RTSP on port 554, an attacker can bypass the device authorization mechanism from the official mobile app that requires a user to physically press on the power button during a connection.

Scores

CVSS v3 7.1
EPSS 0.0025
EPSS Percentile 16.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-288
Status published
Published Mar 24, 2025
Tracked Since Feb 18, 2026