HomeSecurityThinkware Dashcam Vulnerability Allows Credential Extraction

Thinkware Dashcam vulnerability allows credentials to be extracted

A series of critical vulnerabilities in Thinkware's F800 Pro dashcam have revealed systemic security flaws , including the exposure of user credentials in plain text, default authentication bypasses, and insecure data storage practices.

See also: Vulnerability in Chaty Pro plugin puts WordPress sites at risk

Thinkware Dashcam vulnerability

These issues, which were disclosed between November 2024 and March 2025, highlight the risks for millions of devices used worldwide to monitor personal and commercial vehicles.

The most serious vulnerability, identified as CVE-2025-2120, allows attackers with physical access to the Thinkware dashcam to extract Wi-Fi credentials and cloud account details directly from the /tmp/hostapd.conf.

This file stores sensitive data without encryption, allowing attackers to compromise both the local dashcam connectivity and the associated Thinkware Cloud accounts. Researchers confirmed that the credentials remain accessible even after the device is rebooted, posing a permanent risk to users who park vehicles in public or insecure locations.

See also: LibreOffice vulnerability allows execution of arbitrary scripts

The vulnerabilities intersect to create multi-stage attack scenarios:

Default Credential Exploit (CVE-2025-2119): Attackers can connect to the dashcam's Wi-Fi using the default factory password 123456789 , bypassing the required mobile app pairing process

Once connected, they gain unrestricted access to Real-Time Streaming Protocol (RTSP) streaming on port 554 and Telnet services on port 23 , allowing for live video monitoring or historical footage download:

Thinkware Dashcam vulnerability allows credentials to be extracted

Cloud Account Compromise (CVE-2024–53614): A hardcoded AES-256 decryption key in Thinkware Cloud APK (v4.3.46) allows attackers to decrypt login traffic, exposing cloud credentials and granting access to stored material.

File System Manipulation (CVE-2025-2121): Attackers with network access can replace firmware or deploy malware via the dashcam's unprotected file storage system, facilitating permanent backdoors or data corruption:

Thinkware Dashcam vulnerability allows credentials to be extracted

See also: Critical Kibana vulnerability allows arbitrary code execution

The combination of these vulnerabilities in the Thinkware Dashcam allows attackers to:

  • Steal sensitive route footage, traffic sign plates, or driver behavior.
  • Impersonate users via compromised cloud accounts.
  • Develop ransomware targeting fleet operators.
  • Create denial-of-service conditions by hijacking a device's connection socket (CVE-2025-2122).

The exploits operate silently, without visual or audible alerts notifying victims during credential extraction or data exfiltration.

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Source: cybersecuritynews

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS