Impact
The Botslab G980H dash camera firmware contains a hard‑coded cryptographic key and initialization vector used to protect Wi‑Fi credentials transmitted by the device. An adversary who gains physical or logical access to the firmware can extract this material and decrypt the stored credentials, thereby learning the wireless password. With the password, the attacker can connect to the device’s local network, potentially controlling or tampering with the dash cam’s functions and accessing captured footage. The weakness is a misuse of cryptographic parameters, classified as CWE‑321. The vulnerability’s impact is the loss of confidentiality of Wi‑Fi credentials and consequent unauthorized network access to the device.
Affected Systems
The affected product is the Botslab G980H dash camera. No specific firmware versions are listed, so any device running the current firmware that includes the hard‑coded key is susceptible.
Risk and Exploitability
The CVSS score of 6.0 suggests a moderate severity. No exploit probability data is available, and the vulnerability is not listed in CISA’s KEV catalog. The likelihood of exploitation depends on an attacker’s ability to read the firmware or otherwise obtain the cryptographic material; once obtained, the decryption is straightforward and the attacker can immediately use the Wi‑Fi password to gain network access. Adequate asset protection measures, such as network segmentation and device isolation, can reduce the attack surface, but without vendor remediation the risk remains significant.
OpenCVE Enrichment