A vulnerability classified as critical has been found in Thinkware Car Dashcam F800 Pro up to 20250226. Affected is an unknown function of the component File Storage. The manipulation leads to improper access controls. The attack can only be done within the local network. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
History

Wed, 28 May 2025 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Thinkwarestore
Thinkwarestore f800 Pro
Thinkwarestore f800 Pro Firmware
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:h:thinkwarestore:f800_pro:-:*:*:*:*:*:*:*
cpe:2.3:o:thinkwarestore:f800_pro_firmware:*:*:*:*:*:*:*:*
Vendors & Products Thinkwarestore
Thinkwarestore f800 Pro
Thinkwarestore f800 Pro Firmware

Mon, 10 Mar 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 09 Mar 2025 11:15:00 +0000

Type Values Removed Values Added
Description A vulnerability classified as critical has been found in Thinkware Car Dashcam F800 Pro up to 20250226. Affected is an unknown function of the component File Storage. The manipulation leads to improper access controls. The attack can only be done within the local network. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title Thinkware Car Dashcam F800 Pro File Storage access control
Weaknesses CWE-266
CWE-284
References
Metrics cvssV2_0

{'score': 5.8, 'vector': 'AV:A/AC:L/Au:N/C:P/I:P/A:P'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2025-03-09T11:00:07.276Z

Updated: 2025-03-10T15:44:32.074Z

Reserved: 2025-03-08T14:23:38.755Z

Link: CVE-2025-2121

cve-icon Vulnrichment

Updated: 2025-03-10T15:44:28.703Z

cve-icon NVD

Status : Analyzed

Published: 2025-03-09T11:15:36.647

Modified: 2025-05-28T20:26:28.520

Link: CVE-2025-2121

cve-icon Redhat

No data.