An issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Bypassing of Device Pairing can occur. The pairing mechanism relies solely on the connecting device's MAC address. By obtaining the MAC address through network scanning and spoofing it, an attacker can bypass the authentication process and gain full access to the dashcam's features without proper authorization.
The device pairing mechanism is based solely on the MAC address of the connecting device — there are no additional authentication factors. An attacker can perform network scanning to determine the registered MAC address and then spoof it on their own device. After spoofing the MAC address, the authentication process is bypassed, resulting in full access to the dash cam functions.
An attacker without any privileges can gain full, unauthorized access to all functions of the dash cam, including recordings, settings, and data stored on the device, which poses a serious threat to privacy and data integrity.
Apply patches available from the manufacturer according to the references. As a temporary workaround, it is recommended to isolate the device on the network and restrict network scanning capabilities where the dash cam operates.
Forvia Hella HELLA Driving Recorder DR 820 (firmware DR 820); specific firmware versions indicated in manufacturer references
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NHella Dr 820
HWHellaall versionsHella Dr 820 Firmware
OSHellaall versions
Related vulnerabilities
Hardcoded Credentials w Hella Driving Recorder DR 820 (porty 9091/9092)
Hella DR 820: stałe, niezmieniane domyślne dane logowania do sieci Wi-Fi
An issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Remotely Dumping of Video Footage a...
An issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Managing Settings and Obtaining Sen...