A series of critical vulnerabilities in Thinkware's F800 Pro dashcam have revealed systemic security flaws , including the exposure of user credentials in plain text, default authentication bypasses, and insecure data storage practices.
See also: Vulnerability in Chaty Pro plugin puts WordPress sites at risk

These issues, which were disclosed between November 2024 and March 2025, highlight the risks for millions of devices used worldwide to monitor personal and commercial vehicles.
The most serious vulnerability, identified as CVE-2025-2120, allows attackers with physical access to the Thinkware dashcam to extract Wi-Fi credentials and cloud account details directly from the /tmp/hostapd.conf.
This file stores sensitive data without encryption, allowing attackers to compromise both the local dashcam connectivity and the associated Thinkware Cloud accounts. Researchers confirmed that the credentials remain accessible even after the device is rebooted, posing a permanent risk to users who park vehicles in public or insecure locations.
See also: LibreOffice vulnerability allows execution of arbitrary scripts
The vulnerabilities intersect to create multi-stage attack scenarios:
Default Credential Exploit (CVE-2025-2119): Attackers can connect to the dashcam's Wi-Fi using the default factory password 123456789 , bypassing the required mobile app pairing process
Once connected, they gain unrestricted access to Real-Time Streaming Protocol (RTSP) streaming on port 554 and Telnet services on port 23 , allowing for live video monitoring or historical footage download:

Cloud Account Compromise (CVE-2024–53614): A hardcoded AES-256 decryption key in Thinkware Cloud APK (v4.3.46) allows attackers to decrypt login traffic, exposing cloud credentials and granting access to stored material.
File System Manipulation (CVE-2025-2121): Attackers with network access can replace firmware or deploy malware via the dashcam's unprotected file storage system, facilitating permanent backdoors or data corruption:

See also: Critical Kibana vulnerability allows arbitrary code execution
The combination of these vulnerabilities in the Thinkware Dashcam allows attackers to:
- Steal sensitive route footage, traffic sign plates, or driver behavior.
- Impersonate users via compromised cloud accounts.
- Develop ransomware targeting fleet operators.
- Create denial-of-service conditions by hijacking a device's connection socket (CVE-2025-2122).
The exploits operate silently, without visual or audible alerts notifying victims during credential extraction or data exfiltration.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: cybersecuritynews
