CVE-2025-30123
CVSS 3.1 Score 9.8 of 10 (high)
Details
Summary
CVE-2025-30123: A vulnerability was discovered in ROADCAM X3 devices, specifically in their Viidure mobile app. The app contains hardcoded FTP credentials for the FTPX user account, which are accessible to attackers. This issue allows unauthorized access to the device's FTP server, potentially enabling the extraction of sensitive recorded footage. Attackers can exploit this vulnerability remotely, posing a significant security risk to users. Organizations using ROADCAM X3 devices are urged to update their mobile apps and secure their FTP servers to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.