NA
CVSSv2

CVE-2025-30112

CVSSv4: NA | CVSSv3: 7.1 | CVSSv2: NA | VMScore: 810 | EPSS: 0.00039 | KEV: Not Included
Published: 24/03/2025 Updated: 24/03/2025

Vulnerability Summary

70mai Dash Cam 1S Unauthenticated API Access via Network Bypass

A vulnerability exists in 70mai Dash Cam 1S devices that allows unauthorized network access. An attacker can bypass the device's authorization mechanism by connecting directly to the dashcam's network. By accessing the API on port 80 and RTSP on port 554, the attacker can circumvent the security requirement of physically pressing the power button during connection, which is normally enforced by the official mobile app.

Github Repositories

70mai Dashcam 1S Product: www70maicom/cam1s Version: Dash Cam 1S Finding 1 - CVE-2025-30112: Bypass Device Pairing of 70mai Dashcam 1S From the official 70mai mobile app, a user needs to perform authorization by clicking on the physical power button in order to connect to the dashcam’s network However, by connecting to the dashcam’s network and directly a