Insufficiently Protected Credentials in 70mai M300 by 70mai
CVE-2025-6526
Key Information:
Badges
What is CVE-2025-6526?
A vulnerability exists in the 70mai M300 vehicle dashcam that relates to its HTTP Server component, where credentials are insufficiently protected. This flaw allows potential attackers within the local network to exploit insecure access management, making unauthorized operations feasible. While the exploitation complexity is high, the existence and disclosure of the exploit could lead to significant security ramifications for users who have not patched their devices.
Affected Version(s)
M300 20250611
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved