Impact
The Botslab G980H dash camera firmware records sensitive configuration information such as WiFi credentials in diagnostic logs generated during a support operation. After the operation, these logs remain available on removable storage media and contain data that an unauthorized party could read. An attacker who gains physical access to the storage can retrieve the logs and obtain confidential device information, compromising the confidentiality of the system configuration.
Affected Systems
The vulnerability affects Botslab G980H dash cameras. No specific firmware version numbers are listed, indicating that all firmware releases from this product line are potentially impacted.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is physical; the attacker must possess the removable media used during the support process. No network or privileged access is required, but physical access is necessary, suggesting that the exploitation likelihood is contingent on an attacker’s proximity to the device. The data exposed are credentials and configuration details, so the impact is primarily on confidentiality.
OpenCVE Enrichment