CRITICAL🇵🇱 Wersja polska

CVE-2025-30124

CVSS 9.8v3.1pub. 2025-07-28upd. 2026-04-15

An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. When a new SD card is inserted into the dashcam, the existing password is written onto the SD card in cleartext automatically. An attacker with temporary access to the dashcam can switch the SD card to steal this password.

🤖 AI Analysis
How it works

When a new SD card is inserted into the dashcam, the device automatically saves the current access password directly to the card in plaintext format. An attacker needs only brief physical access to the camera — it is sufficient to temporarily swap the SD card and then read the password file outside the device. The mechanism requires no special privileges or user interaction.

Impact

An attacker can obtain the camera's password, enabling full access to its settings and recordings. Compromising the password may also pose a threat if the user uses the same password in other systems or services.

Mitigation & patch

Apply patches available from the manufacturer according to the references. Until a fix is released, it is recommended to restrict physical access to the device and avoid reusing the password set in the camera in other systems.

Who is affected

Marbella K8s Dashcam FF firmware version 2.0.8

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References