CVE-2025-11942 Details
Description
A flaw has been found in 70mai X200 up to 20251010. Affected is an unknown function of the component Pairing. Executing manipulation can lead to missing authentication. It is possible to launch the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability exists in the 70mai Dashcam Omni X200 in versions prior to 20251010, allowing for a bypass of the device pairing authentication mechanism. Users are typically required to physically press the power button to connect the dashcam to the mobile app. However, this vulnerability enables an attacker to connect to the dashcam's network and access the API on port 80 and the RTSP stream on port 554 without any authentication. The lack of authentication on these services facilitates unauthorized access to the dashcam's functionalities.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Oct 20, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/geo-chen/70mai/blob/main/README.md#finding-9-bypass-device-pairing-of-70mai-dashcam-omni-x200 | [email protected] | ExploitThird Party Advisory |
| https://vuldb.com/?ctiid.329021 | [email protected] | Permissions RequiredVDB Entry |
| https://vuldb.com/?id.329021 | [email protected] | Third Party AdvisoryVDB Entry |
| https://vuldb.com/?submit.672520 | [email protected] | Third Party AdvisoryVDB Entry |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-287 | Improper Authentication | [email protected] |
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| 70mai x200 firmware | <= 2025-10-10 |
CPE
Remediation
| |
| 70mai x200 | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Data Remediation | [email protected] |
| Nov 17, 2025 | Initial Analysis | [email protected] |
| Oct 19, 2025 | New CVE Received | [email protected] |