CVE-2025-12915 is a file inclusion vulnerability affecting the 70mai X200 dashcam, specifically within an unknown processing component of its Init Script Handler, in firmware versions up to 20251019. This vulnerability carries a CVSS score of 6.4 (Medium), indicating a high impact on confidentiality, integrity, and availability, but requires local access and has a high attack complexity. Although a public exploit exists, its exploitability is considered difficult, and there is currently no evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2025-10-19CPE matchmatch criteria | cpe:2.3:o:70mai:x200_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.