CVE-2025-30116 – Forvia Hella HELLA Driving Recorder DR 820 Remote Video Footage Dumping and Live Stream Authentication Bypass

The following table lists the changes that have been made to the
CVE-2025-30116 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Mar. 18, 2025

    Action Type Old Value New Value
    Added Description An issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Remotely Dumping of Video Footage and the Live Video Stream can occur. It allows remote attackers to access and download recorded video footage from the SD card via port 9091. Additionally, attackers can connect to port 9092 to stream the live video feed by bypassing the challenge-response authentication mechanism. This exposes sensitive location and personal data.
    Added Reference https://github.com/geo-chen/Hella
    Added Reference https://medium.com/@geochen/cve-draft-hella-driving-recorder-dr-820-ff8c4e2cca26
Share the Post:

Related Posts