i-Drive Dashcams Video Stream Access Control Vulnerability

Vulnerability

A vulnerability exists in i-Drive dashcam models i11 and i12, all firmware versions prior to 20250227. The issue lies in the video footage and live video stream components, where improper access controls allow remote attackers to access and manipulate video data. The vulnerability is particularly concerning as it can be exploited to dump recorded footage, stream live video, and access sensitive information through the dashcam's settings.

Impact

Exploitation of this vulnerability allows for unauthorized remote access to video recordings and live streams from the dashcam, potentially exposing sensitive information such as location data. Additionally, it could be combined with other vulnerabilities to manipulate the dashcam's settings or disrupt the vehicle's battery.

Reproduction

The vulnerability can be reproduced by connecting to the dashcam's Wi-Fi network. Once connected, an attacker can send a crafted command to port 9091 to enumerate and access video recordings stored on the dashcam's SD card. These recordings can be converted from JDR to MP4 format. To stream live footage, the attacker must open a secondary socket to port 9092 and validate the challenge-response key.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
6.6
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.