CVE-2025-30114

CRITICAL

Forvia Hella HELLA Driving Recorder DR 820 - Auth Bypass

Title source: llm
STIX 2.1

Description

An issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Bypassing of Device Pairing can occur. The pairing mechanism relies solely on the connecting device's MAC address. By obtaining the MAC address through network scanning and spoofing it, an attacker can bypass the authentication process and gain full access to the dashcam's features without proper authorization.

Scores

CVSS v3 9.1
EPSS 0.0003
EPSS Percentile 7.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-287
Status published
Products (1)
hella/dr_820_firmware
Published Mar 18, 2025
Tracked Since Feb 18, 2026