BlackVue Dashcam 590X Configuration upload.cgi access control

CVE Details

Basic Information

Title BlackVue Dashcam 590X Configuration upload.cgi access control
Type cve
Published 2025-07-06T00:02:04.767Z
Modified 2025-07-06T00:02:04.767Z

Product Information

Vendor BlackVue
Product Dashcam 590X
Version 20250624

CVSS Information

Base Score 5.3 (MEDIUM)
Attack Vector CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P

AI Analysis

AI Description A vulnerability in the BlackVue Dashcam 590X allows unauthorized access to configuration settings via the upload.cgi file. This could enable local network attackers to modify settings without proper access controls. The vendor has not responded to disclosure attempts, and the exploit is publicly available.
AI Severity Medium
AI Vendor BlackVue
AI Product BlackVue Dashcam 590X
AI Version 20250624

Affected Products

  • BlackVue Dashcam 590X 20250624

Additional Information

CWE List CWE-284, CWE-266
Source VulDB

Description

A vulnerability was found in BlackVue Dashcam 590X up to 20250624. It has been rated as critical. Affected by this issue is some unknown functionality of the file /upload.cgi of the component Configuration Handler. The manipulation leads to improper access controls. The attack needs to be initiated within the local network. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.