CVE-2025-30124

An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. When a new SD card is inserted into the dashcam, the existing password is written onto the SD card in cleartext automatically. An attacker with temporary access to the dashcam can switch the SD card to steal this password.
Configurations

No configuration.

History

30 Jul 2025, 16:15

Type Values Removed Values Added
CWE CWE-312
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
References () https://github.com/geo-chen/Marbella/blob/main/README.md#finding-4---cve-2025-30124-passwords-are-stored-in-plaintext-and-can-be-retrieved-with-physical-contact - () https://github.com/geo-chen/Marbella/blob/main/README.md#finding-4---cve-2025-30124-passwords-are-stored-in-plaintext-and-can-be-retrieved-with-physical-contact -

29 Jul 2025, 14:14

Type Values Removed Values Added
Summary
  • (es) Se detectó un problema en Marbella KR8s Dashcam FF 2.0.8 devices. Al insertar una tarjeta SD nueva en la dashcam, la contraseña existente se escribe automáticamente en texto plano. Un atacante con acceso temporal a la dashcam puede cambiar la tarjeta SD para robar esta contraseña.

28 Jul 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-28 14:15

Updated : 2025-07-30 16:15


NVD link : CVE-2025-30124

Mitre link : CVE-2025-30124

CVE.ORG link : CVE-2025-30124


JSON object : View

Products Affected

No product.

CWE
CWE-312

Cleartext Storage of Sensitive Information