Thinkware Car Dashcam F800 Pro Cleartext Credential Storage Vulnerability

Vulnerability

A vulnerability exists in the Thinkware Car Dashcam F800 Pro, affecting versions through 20250226. The issue arises from the Configuration File Handler component, which improperly processes the file /tmp/hostapd.conf. This mismanagement leads to the storage of user credentials in cleartext on the device. The vulnerability can be exploited physically on the device.

Impact

Exploitation of this vulnerability allows for the extraction of user credentials stored in plain text, which could be used to access the Thinkware Cloud service, potentially compromising sensitive video and audio data from the dashcam.

Reproduction

To reproduce this vulnerability, connect to the dashcam's Wi-Fi network using the default password. Once connected, access the RTSP feed and download video recordings via Telnet. The credentials will be available in cleartext in the /tmp/hostapd.conf file.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
4.6
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.