CVE-2025-30137

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Mar 18, 2025
Updated: Mar 25, 2025
CWE ID 798

Summary

CVE-2025-30137: A significant vulnerability was discovered in the G-Net GNET APK 2.6.2. The issue involves hardcoded credentials that grant unauthorized access to the dashcam's API endpoints on ports 9091 and 9092. An attacker can exploit this by connecting to the GNET SSID and sending a crafted authentication command containing "TibetList" and "000000" to access the settings of the dashcam through port 9091. Similarly, the credentials "admin" and "tibet" provide access to port 9092. This vulnerability poses a serious risk, allowing attackers to manipulate the dashcam's settings and potentially access sensitive data.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share