Thinkware Car Dashcam F800 Pro Device Registration Handler Vulnerability Allowing Default Credential Bypass
Vulnerability
A vulnerability exists in the Thinkware Car Dashcam F800 Pro, affecting versions through 20250226. The issue arises in the Device Registration Handler component, where default credentials are used, allowing an attacker to bypass the second-factor device registration requirement. This vulnerability can be exploited directly on the physical device, although the attack's complexity is considered high.
Impact
Exploitation of this vulnerability allows for unauthorized access to the dashcam's features and data, including the ability to download sensitive video recordings without the owner's knowledge.
Reproduction
To reproduce this vulnerability, connect to the dashcam's Wi-Fi network using the default password. Once connected, access the RTSP feed over port 554 and download video recordings via Telnet on port 23, all without pressing the Wi-Fi button on the dashcam.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
