Loading HuntDB...

GHSA-fhfq-8mf9-qxmx

GitHub Security Advisory

⚠ Unreviewed CRITICAL Has CVE

Advisory Details

An issue was discovered on IROAD Dashcam FX2 devices. Dumping Files Over HTTP and RTSP Without Authentication can occur. It lacks authentication controls on its HTTP and RTSP interfaces, allowing attackers to retrieve sensitive files and video recordings. By connecting to http://192.168.10.1/mnt/extsd/event/, an attacker can download all stored video recordings in an unencrypted manner. Additionally, the RTSP stream on port 8554 is accessible without authentication, allowing an attacker to view live footage.

Related CVEs

Key Information

GHSA ID
GHSA-fhfq-8mf9-qxmx
Published
July 25, 2025 9:33 PM
Last Modified
July 25, 2025 9:33 PM
CVSS Score
9.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 27, 2025 6:35 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.