Tuesday, April 15, 2025
HomeCVE/vulnerabilityThinkware Dashcam Vulnerability Leaks Credentials to Attackers

Thinkware Dashcam Vulnerability Leaks Credentials to Attackers

Published on

SIEM as a Service

Follow Us on Google News

A series of significant security vulnerabilities have been discovered in the Thinkware Dashcam, specifically the F800 Pro model, which could pose serious risks to users’ privacy and security.

These issues include unauthorized access to sensitive data, denial of service, and the ability to write malicious files. Below is a detailed overview of these vulnerabilities and their implications.

Overview of the Vulnerabilities

  1. CVE-2025-2119: Bypass of Device Pairing
    • Description: The authentication mechanism of the Thinkware Dashcam can be bypassed using default credentials. An attacker can connect to the dashcam’s WiFi without going through the Thinkware Cloud app, allowing unauthorized access to the RTSP feed and video recordings via telnet.
    • Impact: This could lead to the theft of sensitive video recordings without the user’s knowledge.
  2. CVE-2025-2122: Denial of Service (DoS)
    • Description: Since the dashcam only supports a single device connection at a time, an attacker could prevent the rightful owner from accessing the device.
    • Impact: This effectively creates a denial-of-service scenario for the legitimate user, potentially leading to security and convenience issues.
  3. CVE-2025-2120: User Credentials Saved in Plain-Text
    • Description: The credentials for the dashcam are stored in plain text in a configuration file, making them easily accessible to anyone with temporary physical access.
    • Impact: This negligence in security practices puts users’ account information at risk of being compromised.
  4. CVE-2025-2121: Unprotected Write Access
    • Description: Once connected to the dashcam, an attacker can write arbitrary files or malware into the device’s storage.
    • Impact: This could lead to the installation of malicious software or disruption of the device’s functionality.
  5. CVE-2024-53614: Hardcoded Decryption Key in Thinkware Cloud APK
    • Description: The Thinkware Cloud APK contains a hardcoded decryption key, which could allow attackers to access encrypted data and execute commands with elevated privileges.
    • Impact: This vulnerability poses a significant threat as it can compromise sensitive video footage stored on the cloud by allowing an attacker to intercept and decode login credentials.

Thinkware was notified about these vulnerabilities on November 12, 2024, via their vulnerability disclosure program.

- Advertisement - Google News

The support team acknowledged the report and forwarded it to their mobile app development team for further evaluation. Despite these efforts, as of the latest update, no official fix has been released to address these issues.

The discovery of these vulnerabilities highlights the importance of robust security measures in IoT devices like dashcams.

Users of Thinkware’s F800 Pro dashcam are advised to take precautions such as changing default passwords and maintaining physical security of their devices.

Additionally, using strong and unique passwords for the Thinkware Cloud is crucial until a comprehensive patch is released.

As the security landscape continues to evolve, manufacturers must prioritize vulnerability testing and patching to protect user data and prevent potential misuse.

Users should remain vigilant about software updates and security advisories related to their devices to mitigate risks effectively.

Are you from SOC/DFIR Teams? – Analyse Malware Incidents & get live Access with ANY.RUN -> Start Now for Free.

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Latest articles

Microsoft Teams File Sharing Unavailable Due to Unexpected Outage

Microsoft Teams users across the globe are experiencing significant disruptions in file-sharing capabilities due...

Cloud Misconfigurations – A Leading Cause of Data Breaches

Cloud computing has transformed the way organizations operate, offering unprecedented scalability, flexibility, and cost...

Security Awareness Metrics That Matter to the CISO

Security awareness has become a critical component of organizational defense strategies, particularly as companies...

New ‘Waiting Thread Hijacking’ Malware Technique Evades Modern Security Measures

Security researchers have unveiled a new malware process injection technique dubbed "Waiting Thread Hijacking"...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Microsoft Teams File Sharing Unavailable Due to Unexpected Outage

Microsoft Teams users across the globe are experiencing significant disruptions in file-sharing capabilities due...

Cloud Misconfigurations – A Leading Cause of Data Breaches

Cloud computing has transformed the way organizations operate, offering unprecedented scalability, flexibility, and cost...

Security Awareness Metrics That Matter to the CISO

Security awareness has become a critical component of organizational defense strategies, particularly as companies...