CRITICAL🇵🇱 Wersja polska

CVE-2025-30114

CVSS 9.1v3.1pub. 2025-03-18upd. 2025-05-22

An issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Bypassing of Device Pairing can occur. The pairing mechanism relies solely on the connecting device's MAC address. By obtaining the MAC address through network scanning and spoofing it, an attacker can bypass the authentication process and gain full access to the dashcam's features without proper authorization.

🤖 AI Analysis
How it works

The device pairing mechanism is based solely on the MAC address of the connecting device — there are no additional authentication factors. An attacker can perform network scanning to determine the registered MAC address and then spoof it on their own device. After spoofing the MAC address, the authentication process is bypassed, resulting in full access to the dash cam functions.

Impact

An attacker without any privileges can gain full, unauthorized access to all functions of the dash cam, including recordings, settings, and data stored on the device, which poses a serious threat to privacy and data integrity.

Mitigation & patch

Apply patches available from the manufacturer according to the references. As a temporary workaround, it is recommended to isolate the device on the network and restrict network scanning capabilities where the dash cam operates.

Who is affected

Forvia Hella HELLA Driving Recorder DR 820 (firmware DR 820); specific firmware versions indicated in manufacturer references

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • Hella Dr 820

    HW
    Hella
    all versions
  • Hella Dr 820 Firmware

    OS
    Hella
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2025-30113CRITICAL9.8PL ✓same product

Hardcoded Credentials w Hella Driving Recorder DR 820 (porty 9091/9092)

CVE-2025-30115CRITICAL9.8PL ✓same product

Hella DR 820: stałe, niezmieniane domyślne dane logowania do sieci Wi-Fi

CVE-2025-30116HIGH7.5same product

An issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Remotely Dumping of Video Footage a...

CVE-2025-30117HIGH7.3same product

An issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Managing Settings and Obtaining Sen...