CVE-2025-30127 Information

Description

An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. Once access is gained either by default common or cracked passwords the video recordings (containing sensitive routes conversations and footage) are open for downloading by creating a socket to command port 7777 and then downloading video via port 7778 and audio via port 7779.

Reference

https://geochen.medium.com/marbella-dashcam-ab40ca41adec https://github.com/geo-chen/Marbella/ https://github.com/geo-chen/Marbella/blob/main/README.md#finding-2—cve-2025-30127-video-recordings-open-to-being-downloaded-via-ports-7777-7778-7779 https://makagps.com/

CNNVD-202508-607 (Published: 2025-08-06)

Share on: