Home

Description

EN DE

A vulnerability has been found in 70mai X200 up to 20251010. Affected by this vulnerability is an unknown functionality of the component HTTP Web Server. The manipulation leads to use of default credentials. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

In 70mai X200 up to 20251010 wurde eine Schwachstelle gefunden. Es betrifft eine unbekannte Funktion der Komponente HTTP Web Server. Durch Manipulieren mit unbekannten Daten kann eine use of default credentials-Schwachstelle ausgenutzt werden. Der Angriff kann remote ausgeführt werden. Die Schwachstelle wurde öffentlich offengelegt und könnte ausgenutzt werden.

PUBLISHED Reserved 2025-10-19 | Published 2025-10-19 | Updated 2025-10-20 | Assigner VulDB




MEDIUM: 6.9CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
HIGH: 7.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:W/RC:R
HIGH: 7.3CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:W/RC:R
7.5AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:W/RC:UR

Problem types

Use of Default Credentials

Product status

20251010
affected

Timeline

2025-10-19:Advisory disclosed
2025-10-19:VulDB entry created
2025-10-19:VulDB entry last update

Credits

geochen (VulDB User) reporter

References

vuldb.com/?id.329022 (VDB-329022 | 70mai X200 HTTP Web Server default credentials) vdb-entry

vuldb.com/?ctiid.329022 (VDB-329022 | CTI Indicators (IOB, IOC)) signature permissions-required

vuldb.com/?submit.672521 (Submit #672521 | 70mai dash cam Omni X200 Improper Access Controls) third-party-advisory

github.com/geo-chen/70mai/blob/main/README.md exploit

cve.org (CVE-2025-11943)

nvd.nist.gov (CVE-2025-11943)

Download JSON