CVE-2025-2343 is a critical hard-coded credentials vulnerability affecting IROAD Dash Cam X5 and X6 devices up to firmware version 20250308, specifically within the Device Pairing component. This vulnerability carries a CVSS score of 7.5 (HIGH), requiring local network access for exploitation, which is considered high complexity and difficult to execute, but could lead to full compromise (confidentiality, integrity, availability). There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| IROAD | Dash Cam X5 | 20250308CNA affected | |
| IROAD | Dash Cam X6 | 20250308CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.