---
id: CVE-2025-11942
title: A flaw has been found in 70mai X200 up to 20251010
summary: >-
  A flaw has been found in 70mai X200 up to 20251010. Affected is an unknown
  function of the component Pairing. Executing manipulation can lead to missing
  authentication. It is possible to launch the attack remotely. The exploit has
  been p…
severity: high
cvss: 7.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-287
  - CWE-306
vendor: 70mai
product: x200_firmware
affected:
  - x200_firmware <= 2025-10-10
published: '2025-10-19'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T22:10:00.563'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-11942'
references:
  - url: >-
      https://github.com/geo-chen/70mai/blob/main/README.md#finding-9-bypass-device-pairing-of-70mai-dashcam-omni-x200
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.329021'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.329021'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.672520'
    label: cna@vuldb.com
tags:
  - nvd
epss: 0.01092
epssPercentile: 0.64391
ingestedAt: '2026-10-08T22:11:53.812Z'
---

## Overview

A flaw has been found in 70mai X200 up to 20251010. Affected is an unknown function of the component Pairing. Executing manipulation can lead to missing authentication. It is possible to launch the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

## Affected

- `x200_firmware <= 2025-10-10`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
