An issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Default Credentials Cannot Be Changed. It uses a fixed default SSID and password ("qwertyuiop"), which cannot be modified by users. The SSID is continuously broadcast, allowing unauthorized access to the device network.
References
| Link | Resource |
|---|---|
| https://github.com/geo-chen/Hella | Third Party Advisory |
| https://medium.com/@geochen/cve-draft-hella-driving-recorder-dr-820-ff8c4e2cca26 | Permissions Required |
Configurations
Configuration 1 (hide)
| AND |
|
History
No history.
Information
Published : 2025-03-18 15:16
Updated : 2025-05-22 19:44
NVD link : CVE-2025-30115
Mitre link : CVE-2025-30115
CVE.ORG link : CVE-2025-30115
JSON object : View
Products Affected
hella
- dr_820
- dr_820_firmware
CWE
CWE-259
Use of Hard-coded Password
