Skip to content

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

6 Commits
 
 

Repository files navigation

LF9

Brand: Brandless

Product: Dashcam

Model: LF9 Pro

Wifi: HiDvr_*

Product Links:

Finding 1 - CVE-2025-6532: Unauthenticated Access of Livestream and Download of Video Recordings

Description: Once connected to the dashcam, an attacker can dump all video recordings via http://192.168.0.1:80/$filename without any http-level authentication. To obtain a list of video recording filenames, the following steps need to be performed via API calls:

  • register the client
  • check work state
  • stop work mode
  • get directory capabilities
  • fetch file list

image

The livestream can also be fetched directly without further authentication at rtsp://192.168.0.1:554/livestream/1

Vulnerability Type: Incorrect Access Control

Vendor of Product: HiDvr

Affected Product Code Base: LF9 Pro

Affected Component: Video storage and live feed

Attack Type: Remote

Impact Code execution: False

Impact Information Disclosure: True

Attack Vectors: An attacker connected to the dashcam's network can access the live feed and dump all sensitive video recordings.

Has vendor confirmed or acknowledged the vulnerability?: No

Product Images:

image

image

image

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors