CVE-2025-30140 Details
Description
An issue was discovered on G-Net Dashcam BB GONX devices. A Public Domain name is Used for the Internal Domain Name. It uses an unregistered public domain name as an internal domain, creating a security risk. This domain was not owned by GNET originally, allowing an attacker to register it and potentially intercept sensitive device traffic (it has since been registered by the vulnerability discoverer). If the dashcam or related services attempt to resolve this domain over the public Internet instead of locally, it could lead to data exfiltration or man-in-the-middle attacks.
A vulnerability exists in G-Net Dashcam BB GONX devices due to the use of an unregistered public domain name as an internal domain. This misconfiguration creates a security risk, as an attacker could register the domain and intercept sensitive device traffic. If the dashcam or related services resolve this domain over the public Internet instead of locally, it could lead to data exfiltration or man-in-the-middle attacks.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 25, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/geo-chen/GNET | [email protected] | Third Party Advisory |
| https://www.gnetsystem.com/eng/product/list?viewMode=view&idx=246&ca_id=0201 | [email protected] | Product |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-284 | Improper Access Control | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| gnetsystem g-onx firmware | All versions |
CPE
Remediation
| |
| gnetsystem g-onx | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jul 1, 2025 | Initial Analysis | [email protected] |
| Mar 25, 2025 | CVE Modified | CISA-ADP |
| Mar 18, 2025 | New CVE Received | [email protected] |