CVE-2025-30138
Managing Settings and Obtaining Sensitive Data and Sabotaging Car Battery can be performed by unauthorized persons.
Does this matter?
Lower severity and a low EPSS score (0.18%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered on G-Net Dashcam BB GONX devices. Managing Settings and Obtaining Sensitive Data and Sabotaging Car Battery can be performed by unauthorized persons. It allows unauthorized users to modify critical system settings once connected to its network. Attackers can extract sensitive car and driver information, mute dashcam alerts to prevent detection, disable recording functionality, or even factory reset the device. Additionally, they can disable battery protection, causing the dashcam to drain the car battery when left on overnight. These actions not only compromise privacy but also pose potential physical harm by rendering the dashcam non-functional or causing vehicle battery failure.
- CVSS 3.1
- 4.6 MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 0.18% probability · 8th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-284
- Affected
- gnetsystem/g-onx firmware
- Source
- cve@mitre.org
References
- https://github.com/geo-chen/GNETThird Party Advisory
- https://www.gnetsystem.com/eng/product/list?viewMode=view&idx=246&ca_id=0201Product
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.