CVE-2025-30123

An issue was discovered on ROADCAM X3 devices. The mobile app APK (Viidure) contains hardcoded FTP credentials for the FTPX user account, enabling attackers to gain unauthorized access and extract sensitive recorded footage from the device.
Configurations

No configuration.

History

21 Mar 2025, 18:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE CWE-798
Summary
  • (es) Se detectó un problema en los dispositivos ROADCAM X3. El APK de la aplicación móvil (Viidure) contiene credenciales FTP codificadas para la cuenta de usuario FTPX, lo que permite a los atacantes obtener acceso no autorizado y extraer grabaciones confidenciales del dispositivo.

18 Mar 2025, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-18 15:16

Updated : 2025-03-21 18:15


NVD link : CVE-2025-30123

Mitre link : CVE-2025-30123

CVE.ORG link : CVE-2025-30123


JSON object : View

Products Affected

No product.

CWE
CWE-798

Use of Hard-coded Credentials