CVE-2025-30142

HIGH

G-Net Dashcam BB GONX - Auth Bypass

Title source: llm
STIX 2.1

Description

An issue was discovered on G-Net Dashcam BB GONX devices. Bypassing of Device Pairing can occur. It uses MAC address verification as the sole mechanism for recognizing paired devices, allowing attackers to bypass authentication. By capturing the MAC address of an already-paired device through ARP scanning or other means, an attacker can spoof the MAC address and connect to the dashcam without going through the pairing process. This enables full access to the device.

Scores

CVSS v3 8.1
EPSS 0.0002
EPSS Percentile 6.3%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-290
Status published
Products (1)
gnetsystem/g-onx_firmware
Published Mar 18, 2025
Tracked Since Feb 18, 2026