An issue was discovered on ROADCAM X3 devices. The mobile app APK (Viidure) contains hardcoded FTP credentials for the FTPX user account, enabling attackers to gain unauthorized access and extract sensitive recorded footage from the device.
References
Configurations
No configuration.
History
21 Mar 2025, 18:15
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
CWE | CWE-798 | |
Summary |
|
18 Mar 2025, 15:16
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-03-18 15:16
Updated : 2025-03-21 18:15
NVD link : CVE-2025-30123
Mitre link : CVE-2025-30123
CVE.ORG link : CVE-2025-30123
JSON object : View
Products Affected
No product.
CWE
CWE-798
Use of Hard-coded Credentials