CVE-2025-2356
CVSS 3.1 Score 7.1 of 10 (high)
Details
Summary
CVE-2025-2356 is a newly disclosed vulnerability affecting BlackVue App 3.65 on Android devices. This issue is considered problematic and impacts the deviceDelete function within the API Handler component. Attackers can exploit this vulnerability by using a get request method with sensitive query strings, potentially initiating the attack remotely. The complexity of an attack is rather high, and the exploitability is reported as difficult, but the exploit has been disclosed to the public, increasing the risk of potential attacks. Despite early contact with the vendor, no response has been received.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.