Description
The Botslab G980H dash camera firmware uses a hard-coded cryptographic key and initialization vector to protect WiFi credentials communicated by the device. An attacker who obtains the protected credential and extracts the cryptographic material from the firmware could recover the WiFi password and gain unauthorized access to the device network.
Published: 2026-09-24
Score: 6 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized Device Network Access
Action: Contact Vendor
AI Analysis

Impact

The Botslab G980H dash camera firmware contains a hard‑coded cryptographic key and initialization vector used to protect Wi‑Fi credentials transmitted by the device. An adversary who gains physical or logical access to the firmware can extract this material and decrypt the stored credentials, thereby learning the wireless password. With the password, the attacker can connect to the device’s local network, potentially controlling or tampering with the dash cam’s functions and accessing captured footage. The weakness is a misuse of cryptographic parameters, classified as CWE‑321. The vulnerability’s impact is the loss of confidentiality of Wi‑Fi credentials and consequent unauthorized network access to the device.

Affected Systems

The affected product is the Botslab G980H dash camera. No specific firmware versions are listed, so any device running the current firmware that includes the hard‑coded key is susceptible.

Risk and Exploitability

The CVSS score of 6.0 suggests a moderate severity. No exploit probability data is available, and the vulnerability is not listed in CISA’s KEV catalog. The likelihood of exploitation depends on an attacker’s ability to read the firmware or otherwise obtain the cryptographic material; once obtained, the decryption is straightforward and the attacker can immediately use the Wi‑Fi password to gain network access. Adequate asset protection measures, such as network segmentation and device isolation, can reduce the attack surface, but without vendor remediation the risk remains significant.

Generated by OpenCVE AI on September 25, 2026 at 03:10 UTC.

Remediation

Vendor Workaround

Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information: https://www.botslab.com/pages/about-botslab


OpenCVE Recommended Actions

  • Reach out to Botslab to request a firmware update or guidance on mitigating the vulnerability
  • If a firmware update is unavailable, change the device’s default Wi‑Fi credentials to a strong, unique password and ensure the new password is not the same as the hard‑coded default
  • Apply network segmentation or firewall rules to restrict the dash camera’s access to the local network, limiting potential damage if the credentials are compromised

Generated by OpenCVE AI on September 25, 2026 at 03:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description The Botslab G980H dash camera firmware uses a hard-coded cryptographic key and initialization vector to protect WiFi credentials communicated by the device. An attacker who obtains the protected credential and extracts the cryptographic material from the firmware could recover the WiFi password and gain unauthorized access to the device network.
Title Botslab G980H Dashcams Use of Hard-coded Cryptographic Key
Weaknesses CWE-321
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-09-24T20:11:19.170Z

Reserved: 2026-09-10T15:25:29.827Z

Link: CVE-2026-75558

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-24T21:18:36.203

Modified: 2026-09-24T21:25:27.050

Link: CVE-2026-75558

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-25T03:15:14Z

Weaknesses
  • CWE-321

    Use of Hard-coded Cryptographic Key