CVE-2025-30112 Details
Description
On 70mai Dash Cam 1S devices, by connecting directly to the dashcam's network and accessing the API on port 80 and RTSP on port 554, an attacker can bypass the device authorization mechanism from the official mobile app that requires a user to physically press on the power button during a connection.
An authorization bypass vulnerability has been identified in the 70mai Dash Cam 1S. By connecting directly to the dashcam's Wi-Fi network and accessing the API on port 80 or the RTSP stream on port 554, an attacker can circumvent the authorization mechanism required by the official mobile app. This app-based authorization mandates that a user physically press the power button on the dashcam during the connection process.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Mar 24, 2025CISA-ADP
Assessed Mar 24, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/geo-chen/70mai/blob/main/README.md#finding-1---cve-2025-30112-bypass-device-pairing-of-70mai-dashcam-1s | [email protected] | ExploitTechnical Description |
| https://www.70mai.com/cam1s/ | [email protected] | ProductVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-288 | Authentication Bypass Using an Alternate Path or Channel | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| 70mai Dash Cam 1S | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 24, 2025 | CVE Modified | CISA-ADP |
| Mar 24, 2025 | New CVE Received | [email protected] |
Volerion