CVE-2025-6525 Details
Description
A vulnerability classified as problematic was found in 70mai 1S up to 20250611. This vulnerability affects unknown code of the file /cgi-bin/Config.cgi?action=set of the component Configuration Handler. The manipulation leads to improper authorization. The attack needs to be approached within the local network. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability allowing unauthorized configuration changes has been identified in the 70mai Dash Cam 1S, affecting versions through 20250611. The issue resides in the Configuration Handler, specifically within the file '/cgi-bin/Config.cgi?action=set'. This vulnerability stems from improper authorization, allowing attackers to manipulate settings without notification or physical interaction with the device. Exploitation can disrupt the dash cam's battery protection, potentially draining the car's battery.
It is recommended to implement proper firewall rules to block unauthorized access to the dash cam's configuration endpoints.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 23, 2025CISA-ADP
Assessed Jun 24, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/geo-chen/70mai/blob/main/README.md#finding-3-unauthorised-configuration-change | [email protected] | Exploit |
| https://vuldb.com/?ctiid.313642 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/?id.313642 | [email protected] | AdvisoryExploitPartial ContentRemedy |
| https://vuldb.com/?submit.595446 | [email protected] | Exploit |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-266 | Incorrect Privilege Assignment | [email protected] |
| CWE-285 | Improper Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| 70mai 1S | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Data Remediation | [email protected] |
| Jun 23, 2025 | New CVE Received | [email protected] |
Volerion