CVE-2025-30118

An issue was discovered on the Audi Universal Traffic Recorder 2.88. It has Susceptibility to denial of service. It uses the same default credentials for all devices and does not implement proper multi-device authentication, allowing attackers to deny the owner access by occupying the only available connection. The SSID remains broadcast at all times, increasing exposure to potential attacks.
Configurations

No configuration.

History

27 Mar 2025, 16:45

Type Values Removed Values Added
Summary
  • (es) Se detectó un problema en Audi Universal Traffic Recorder 2.88. Presenta vulnerabilidad a la denegación de servicio. Utiliza las mismas credenciales predeterminadas para todos los dispositivos y no implementa una autenticación multidispositivo adecuada, lo que permite a los atacantes denegar el acceso al propietario ocupando la única conexión disponible. El SSID se mantiene en constante difusión, lo que aumenta la exposición a posibles ataques.

26 Mar 2025, 15:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CWE CWE-798

25 Mar 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-25 20:15

Updated : 2025-03-27 16:45


NVD link : CVE-2025-30118

Mitre link : CVE-2025-30118

CVE.ORG link : CVE-2025-30118


JSON object : View

Products Affected

No product.

CWE
CWE-798

Use of Hard-coded Credentials