CVE-2025-2346
Last modified
CVE-2025-2346 is a medium-severity vulnerability rated 6.3/10 on the CVSS scale. A vulnerability has been found in IROAD Dash Cam X5 and Dash Cam X6 up to 20250308 and classified as problematic. This vulnerability affects unknown code of the component Domain Handler. EPSS estimates a 0.21% chance of exploitation in the next 30 days.
Description
A vulnerability has been found in IROAD Dash Cam X5 and Dash Cam X6 up to 20250308 and classified as problematic. This vulnerability affects unknown code of the component Domain Handler. The manipulation of the argument Domain Name leads to origin validation error. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-2346?
How severe is CVE-2025-2346?
How do I fix CVE-2025-2346?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-23454Improper Neutralization of Input During Web Page Generation …7.1
- CVE-2025-23455Cross-Site Request Forgery (CSRF) vulnerability in Master So…7.1
- CVE-2025-23456Cross-Site Request Forgery (CSRF) vulnerability in Oddthinki…7.1
- CVE-2025-23457Improper Neutralization of Input During Web Page Generation …7.1
- CVE-2025-23458Improper Neutralization of Input During Web Page Generation …7.1
- CVE-2025-23459Improper Neutralization of Input During Web Page Generation …7.1
- CVE-2025-23460Improper Neutralization of Input During Web Page Generation …7.1
- CVE-2025-23461Improper Neutralization of Input During Web Page Generation …7.1
- CVE-2025-23462Improper Neutralization of Input During Web Page Generation …7.1
- CVE-2025-23463Cross-Site Request Forgery (CSRF) vulnerability in Mukesh Da…7.1
- CVE-2025-23464Improper Neutralization of Input During Web Page Generation …7.1
- CVE-2025-23465Improper Neutralization of Input During Web Page Generation …7.1
Are you affected by CVE-2025-2346?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
