Thinkware Car Dashcam F800 Pro Device Registration Handler Vulnerability Allowing Default Credential Bypass

Vulnerability

A vulnerability exists in the Thinkware Car Dashcam F800 Pro, affecting versions through 20250226. The issue arises in the Device Registration Handler component, where default credentials are used, allowing an attacker to bypass the second-factor device registration requirement. This vulnerability can be exploited directly on the physical device, although the attack's complexity is considered high.

Impact

Exploitation of this vulnerability allows for unauthorized access to the dashcam's features and data, including the ability to download sensitive video recordings without the owner's knowledge.

Reproduction

To reproduce this vulnerability, connect to the dashcam's Wi-Fi network using the default password. Once connected, access the RTSP feed over port 554 and download video recordings via Telnet on port 23, all without pressing the Wi-Fi button on the dashcam.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
3.1
exploitability
4.6
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.