VendorsIroadaufx2_firmwareall versions
Vulnerabilities

Iroadau fx2 Firmware

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2025-30131
An issue was discovered on IROAD Dashcam FX2 devices. An unauthenticated file upload endpoint can be leveraged to execute arbitrary commands by uploading a CGI-based webshell. Once a file is uploaded, the attacker can execute commands with root privileges, gaining full control over the dashcam. Additionally, by uploading a netcat (nc) binary, the attacker can establish a reverse shell, maintaining persistent remote and privileged access to the device. This allows complete device takeover.
Published 2025-06-26 · Analyzed
9.8EPSS 0.006
CVE-2025-30133
An issue was discovered on IROAD Dashcam FX2 devices. Bypass of Device Pairing/Registration can occur. It requires device registration via the "IROAD X View" app for authentication, but its HTTP server lacks this restriction. Once connected to the dashcam's Wi-Fi network via the default password ("qwertyuiop"), an attacker can directly access the HTTP server at http://192.168.10.1 without undergoing the pairing process. Additionally, no alert is triggered on the device when an attacker connects, making this intrusion completely silent.
Published 2025-07-28 · Analyzed
9.8EPSS 0.005
CVE-2025-30135
An issue was discovered on IROAD Dashcam FX2 devices. Dumping Files Over HTTP and RTSP Without Authentication can occur. It lacks authentication controls on its HTTP and RTSP interfaces, allowing attackers to retrieve sensitive files and video recordings. By connecting to http://192.168.10.1/mnt/extsd/event/, an attacker can download all stored video recordings in an unencrypted manner. Additionally, the RTSP stream on port 8554 is accessible without authentication, allowing an attacker to view live footage.
Published 2025-07-25 · Analyzed
9.4EPSS 0.006
CVE-2025-2350
IROAD Dash Cam FX2 upload_file unrestricted upload
Published 2025-03-16 · Analyzed
7.8EPSS 0.003
CVE-2025-2347
IROAD Dash Cam FX2 Device Registration default password
Published 2025-03-16 · Analyzed
7.8EPSS 0.002
CVE-2025-2348
IROAD Dash Cam FX2 HTTP/RTSP event information disclosure
Published 2025-03-16 · Analyzed
5.5EPSS 0.002
CVE-2025-2349
IROAD Dash Cam FX2 Password Hash passwd weak password hash
Published 2025-03-16 · Analyzed
4.7EPSS 0.002