An issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Default Credentials Cannot Be Changed. It uses a fixed default SSID and password ("qwertyuiop"), which cannot be modified by users. The SSID is continuously broadcast, allowing unauthorized access to the device network.
The product contains a hard-coded password, which it uses for its own inbound authentication or for outbound communication to external components.
Link | Tags |
---|---|
https://medium.com/@geochen/cve-draft-hella-driving-recorder-dr-820-ff8c4e2cca26 | permissions required |
https://github.com/geo-chen/Hella | third party advisory |