CVE-2025-30124CRITICAL 9.8EPSS p19.0%

CVE-2025-30124CVE-2025-30124

Description

An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. When a new SD card is inserted into the dashcam, the existing password is written onto the SD card in cleartext automatically. An attacker with temporary access to the dashcam can switch the SD card to steal this password.

Scoring

CVSS 3.19.8 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS0.27% probability of exploitation · percentile 19.0% · 2026-06-18T12:00:27Z
Published2025-07-28
Last modified2026-04-15

Underlying weaknesses· 1

CWE-312

References

  1. https://geochen.medium.com/marbella-dashcam-ab40ca41adec
  2. https://github.com/geo-chen/Marbella/
  3. https://github.com/geo-chen/Marbella/blob/main/README.md#finding-4---cve-2025-30124-passwords-are-stored-in-plaintext-and-can-be-retrieved-with-physical-contact
  4. https://makagps.com/
  5. https://github.com/geo-chen/Marbella/blob/main/README.md#finding-4---cve-2025-30124-passwords-are-stored-in-plaintext-and-can-be-retrieved-with-physical-contact

1

TypeTargetConfidenceTier
WeaknessCleartext Storage of Sensitive Informationcwe-3120%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2025-30125
CVE
CVE-2025-30127
CVE
CVE-2025-30114
CVE
CVE-2025-30122
CVE
CVE-2025-30113
CVE
CVE-2025-30115
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.