CVE-2025-30125 – Marbella KR8s Dashcam Weak Password Authentication Vulnerability

The following table lists the changes that have been made to the
CVE-2025-30125 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Jul. 28, 2025

    Action Type Old Value New Value
    Added Description An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. All dashcams were shipped with the same default credentials of 12345678, which creates an insecure-by-default condition. For users who change their passwords, it’s limited to 8 characters. These short passwords can be cracked in 8 hours via low-end commercial cloud resources.
    Added Reference https://geochen.medium.com/marbella-dashcam-ab40ca41ade
    Added Reference https://github.com/geo-chen/Marbella/
    Added Reference https://github.com/geo-chen/Marbella/blob/main/README.md#finding-1—cve-2025-30125-same-default-credentials-and-limited-password-combinations
    Added Reference https://makagps.com/
    Added Reference https://www.protiviti.com/sg-en/blogs/6259-8-character-password-still-dead
Share the Post:

Related Posts