CNNVD-202510-2550 Information

CNNVD ID

CNNVD-202510-2550

CVE-2025-11942

  • CNNVD Published: 2025-10-19

Description (Chinese)

70mai X200是中国70迈(70mai)公司的一个只能云台行车记录仪。 70mai X200 20251010及之前版本存在访问控制错误漏洞,该漏洞源于配对组件缺少身份验证,可能导致远程攻击。

Description (English)

70mai X200 is a cloud-only car recorder at 70mai (70mai) in China. 70mai X200 20251010 and previous versions had access control errors, which stemmed from the lack of identification of pair components, which could lead to a remote attack.

Hazard Level

Medium

Vulnerability Type

访问控制错误

Affected Vendor

70迈

Published

2025-10-19

Last Modified

2026-02-24

References

https://vuldb.com/?ctiid.329021 https://github.com/geo-chen/70mai/blob/main/README.md#finding-9-bypass-device-pairing-of-70mai-dashcam-omni-x200 https://vuldb.com/?id.329021 https://vuldb.com/?submit.672520 https://access.redhat.com/security/cve/cve-2025-11942

Share on: