A vulnerability was found in Thinkware Car Dashcam F800 Pro up to 20250226. It has been rated as problematic. This issue affects some unknown processing of the file /tmp/hostapd.conf of the component Configuration File Handler. The manipulation leads to cleartext storage in a file or on disk. It is possible to launch the attack on the physical device. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
History

Mon, 10 Mar 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 09 Mar 2025 10:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in Thinkware Car Dashcam F800 Pro up to 20250226. It has been rated as problematic. This issue affects some unknown processing of the file /tmp/hostapd.conf of the component Configuration File Handler. The manipulation leads to cleartext storage in a file or on disk. It is possible to launch the attack on the physical device. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title Thinkware Car Dashcam F800 Pro Configuration File hostapd.conf cleartext storage in a file or on disk
Weaknesses CWE-312
CWE-313
References
Metrics cvssV2_0

{'score': 1.7, 'vector': 'AV:L/AC:L/Au:S/C:P/I:N/A:N'}

cvssV3_0

{'score': 2.1, 'vector': 'CVSS:3.0/AV:P/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

cvssV3_1

{'score': 2.1, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 2.4, 'vector': 'CVSS:4.0/AV:P/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2025-03-09T10:31:03.993Z

Updated: 2025-03-10T15:45:15.593Z

Reserved: 2025-03-08T14:23:35.744Z

Link: CVE-2025-2120

cve-icon Vulnrichment

Updated: 2025-03-10T15:45:12.094Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-03-09T11:15:35.023

Modified: 2025-03-10T16:15:14.347

Link: CVE-2025-2120

cve-icon Redhat

No data.