CVE-2025-30133 Details
Description
An issue was discovered on IROAD Dashcam FX2 devices. Bypass of Device Pairing/Registration can occur. It requires device registration via the "IROAD X View" app for authentication, but its HTTP server lacks this restriction. Once connected to the dashcam's Wi-Fi network via the default password ("qwertyuiop"), an attacker can directly access the HTTP server at http://192.168.10.1 without undergoing the pairing process. Additionally, no alert is triggered on the device when an attacker connects, making this intrusion completely silent.
A vulnerability exists in the IROAD Dashcam FX2 that allows attackers to bypass the device pairing and registration process. This issue arises because the dashcam's HTTP server does not enforce pairing requirements, leaving the device open to unauthorized access. To exploit this vulnerability, an attacker must connect to the dashcam's Wi-Fi network using the default password. Once connected, they can access the HTTP server without completing the pairing process. This intrusion goes undetected, as the dashcam does not alert the user when a connection is made.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 30, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-284 | Improper Access Control | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| iroadau fx2 firmware | All versions |
CPE
Remediation
| |
| iroadau fx2 | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 6, 2025 | Initial Analysis | [email protected] |
| Jul 30, 2025 | CVE Modified | CISA-ADP |
| Jul 28, 2025 | New CVE Received | [email protected] |