Vulnerability Description
An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. All dashcams were shipped with the same default credentials of 12345678, which creates an insecure-by-default condition. For users who change their passwords, it's limited to 8 characters. These short passwords can be cracked in 8 hours via low-end commercial cloud resources.
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
- https://geochen.medium.com/marbella-dashcam-ab40ca41ade
- https://github.com/geo-chen/Marbella/
- https://github.com/geo-chen/Marbella/blob/main/README.md#finding-1---cve-2025-30
- https://makagps.com/
- https://www.protiviti.com/sg-en/blogs/6259-8-character-password-still-dead
- https://github.com/geo-chen/Marbella/blob/main/README.md#finding-1---cve-2025-30
FAQ
What is CVE-2025-30125?
CVE-2025-30125 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. All dashcams were shipped with the same default credentials of 12345678, which creates an insecure-by-default condition. For users wh...
How severe is CVE-2025-30125?
CVE-2025-30125 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-30125?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.