An issue was discovered on G-Net Dashcam BB GONX devices. Default credentials for SSID cannot be changed. It broadcasts a fixed SSID with default credentials that cannot be changed. This allows any nearby attacker to connect to the dashcam's network without restriction. Once connected, an attacker can sniff on connected devices such as the user's smartphone. The SSID is also always broadcasted.
History

Tue, 25 Mar 2025 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-1392
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 18 Mar 2025 20:15:00 +0000

Type Values Removed Values Added
Description An issue was discovered on G-Net Dashcam BB GONX devices. Default credentials for SSID cannot be changed. It broadcasts a fixed SSID with default credentials that cannot be changed. This allows any nearby attacker to connect to the dashcam's network without restriction. Once connected, an attacker can sniff on connected devices such as the user's smartphone. The SSID is also always broadcasted.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-03-25T15:38:45.471Z

Reserved: 2025-03-17T00:00:00.000Z

Link: CVE-2025-30139

cve-icon Vulnrichment

Updated: 2025-03-25T15:38:37.209Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-03-18T20:15:26.597

Modified: 2025-03-25T16:15:26.627

Link: CVE-2025-30139

cve-icon Redhat

No data.