CVE-2025-2356

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Mar 17, 2025
CWE ID 79

Summary

CVE-2025-2356 is a newly disclosed vulnerability affecting BlackVue App 3.65 on Android devices. This issue is considered problematic and impacts the deviceDelete function within the API Handler component. Attackers can exploit this vulnerability by using a get request method with sensitive query strings, potentially initiating the attack remotely. The complexity of an attack is rather high, and the exploitability is reported as difficult, but the exploit has been disclosed to the public, increasing the risk of potential attacks. Despite early contact with the vendor, no response has been received.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share