Iroadau's vulnerability footprint centers on the FX2 network appliance and its firmware, a narrowly scoped but strategically positioned product in critical infrastructure deployments. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and recur through weakness classes including improper access control, unrestricted file uploads, sensitive information exposure, and inadequate encryption strength—flaws that pose direct risk to the integrity and confidentiality of traffic flowing through the appliance. Defenders should prioritize inventory and patching of deployed FX2 instances given the severity profile of reported flaws; live exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Iroadau over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-30133CRITICAL An issue was discovered on IROAD Dashcam FX2 devices. Bypass of Device Pairing/Registration can occur. It requires device registration via the "IROAD X View" app for authentication | Jul 28, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-30135CRITICAL An issue was discovered on IROAD Dashcam FX2 devices. Dumping Files Over HTTP and RTSP Without Authentication can occur. It lacks authentication controls on its HTTP and RTSP inter | Jul 25, 2025 | 9.4 | 30 | NO | NO |
CVE-2025-30131CRITICAL An issue was discovered on IROAD Dashcam FX2 devices. An unauthenticated file upload endpoint can be leveraged to execute arbitrary commands by uploading a CGI-based webshell. Once | Jun 26, 2025 | 9.8 | 26 | NO | NO |
CVE-2025-2350HIGH A vulnerability was found in IROAD Dash Cam FX2 up to 20250308. It has been rated as critical. Affected by this issue is some unknown functionality of the file /action/upload_file. | Mar 16, 2025 | 7.8 | 21 | NO | NO |
CVE-2025-2347HIGH A vulnerability was found in IROAD Dash Cam FX2 up to 20250308 and classified as problematic. This issue affects some unknown processing of the component Device Registration. The m | Mar 16, 2025 | 7.8 | 21 | NO | NO |
CVE-2025-2348MEDIUM A vulnerability was found in IROAD Dash Cam FX2 up to 20250308. It has been classified as problematic. Affected is an unknown function of the file /mnt/extsd/event/ of the componen | Mar 16, 2025 | 5.5 | 17 | NO | NO |
CVE-2025-2349MEDIUM A vulnerability was found in IROAD Dash Cam FX2 up to 20250308. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /etc/pas | Mar 16, 2025 | 4.7 | 15 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Iroadau.
Media articles that mention a CVE ID that affects a product developed by Iroadau — matched by CVE ID, not by vendor name.