File Storage Vulnerability in Thinkware Car Dashcam F800 Pro
CVE-2025-2120
Key Information:
- Vendor
Thinkware
- Status
- Vendor
- CVE Published:
- 9 March 2025
Badges
What is CVE-2025-2120?
A cleartext storage vulnerability has been identified in the Thinkware Car Dashcam F800 Pro, specifically in the handling of the configuration file /tmp/hostapd.conf. This weakness allows sensitive information to be stored in an unencrypted format on the device, potentially exposing it to unauthorized access. This vulnerability can be exploited physically, making it crucial for users to safeguard their devices. Despite early notification of this issue, the vendor has yet to respond.
Affected Version(s)
Car Dashcam F800 Pro 20250226
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
