cvedb.io
CVE-2025-30114
CRITICAL · CVSS 9.1
EPSS exploitation probability: 0%
Published 2025-03-18T15:16:02.583 · Last modified 2026-06-17T09:08:11.340

Summary

An issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Bypassing of Device Pairing can occur. The pairing mechanism relies solely on the connecting device's MAC address. By obtaining the MAC address through network scanning and spoofing it, an attacker can bypass the authentication process and gain full access to the dashcam's features without proper authorization.

Affected products

hella — dr_820_firmware

Does this affect you?

Add your gear to cvedb and we'll alert you only when hella ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.