← back
CVE-2025-11943mediumCWE-1392

70mai X200 HTTP Web Server default credentials

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 6.9epss 0.7%
exploitation probability
0.7%top 51% of all CVEs
observed exploitation
nono source reports it
In short

The 70mai X200 dashcam uses default credentials in its web server that cannot be changed, allowing anyone on the network to access and control the device without proper authentication.

Technical detail

The HTTP Web Server component in 70mai X200 (firmware up to 20251010) contains hardcoded default credentials with no option to modify them. An unauthenticated remote attacker can access the web interface and perform unauthorized actions on the device. Public exploits are available and the vendor has not addressed this issue.

Summary generated and translated by AI from the official description.
A vulnerability has been found in 70mai X200 up to 20251010. Affected by this vulnerability is an unknown functionality of the component HTTP Web Server. The manipulation leads to use of default credentials. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Affected products
70mai · X200