70mai Dashcam 15 Finding 1: CVE-2025-9812 - Bypass Device Pairing of 70mai Dashcam 15 CVE ID: CVE-2025-9812 Severity: High Description: An attacker can bypass the device pairing process by exploiting a vulnerability in the authentication mechanism. Impact: Unauthorized access to the dashcam's features and data. Finding 2: CVE-2025-9824 - Unauthenticated File Storage/Allowing Remote Dumping of Video Footage and Live Video Stream CVE ID: CVE-2025-9824 Severity: Critical Description: The dashcam allows unauthenticated storage of files, enabling remote dumping of video footage and live video streams. Impact: Exposure of sensitive video data. Finding 3: CVE-2025-9825 - Unauthorized Configuration Change CVE ID: CVE-2025-9825 Severity: High Description: An attacker can make unauthorized configuration changes to the dashcam. Impact: Potential for altering the dashcam's settings and functionality. 70mai Dashcam M300 Finding 4: CVE-2025-9826 - Exposed Root Password via Unauthorized HTTP Access CVE ID: CVE-2025-9826 Severity: Critical Description: The root password is exposed through unauthorized HTTP access. Impact: Full system compromise. Finding 5: CVE-2025-9827 - Remotely Dump All Sensitive Video & Audio Recordings CVE ID: CVE-2025-9827 Severity: Critical Description: An attacker can remotely dump all sensitive video and audio recordings from the dashcam. Impact: Exposure of all recorded data. Finding 6: CVE-2025-9828 - Unauthenticated Live Video Stream CVE ID: CVE-2025-9828 Severity: High Description: The live video stream is accessible without authentication. Impact: Real-time surveillance by unauthorized parties. Finding 7: CVE-2025-9829 - Remotely Upload Malicious Files and Execute Code CVE ID: CVE-2025-9829 Severity: Critical Description: An attacker can remotely upload malicious files and execute code on the dashcam. Impact: System compromise and potential damage. Finding 8: CVE-2025-9830 - Remotely Crashing the Dashcam CVE ID: CVE-2025-9830 Severity: Medium Description: An attacker can remotely crash the dashcam. Impact: Disruption of the dashcam's operation.