CVE-2025-30140

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Mar 18, 2025
Updated: Mar 25, 2025
CWE ID 284

Summary

CVE-2025-30140: A vulnerability was discovered in G-Net Dashcam BB GONX devices, which uses an unregistered public domain name as an internal domain. This security risk arises because the domain was not originally owned by GNET, allowing an attacker to potentially register it and intercept sensitive traffic. If the dashcam or related services attempt to resolve this domain over the public Internet instead of locally, it could result in data exfiltration or man-in-the-middle attacks. This vulnerability has since been addressed by the registrations of the domain by the vulnerability discoverer.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share