Impact
A flaw in the Botslab G980H dash camera firmware allows any nearby Bluetooth Low Energy device to read GATT characteristics without authenticating or binding, enabling an attacker to capture device identifiers, firmware information, and protected WiFi credentials. The vulnerability corresponds to an authentication bypass weakness (CWE‑306) and could lead to unauthorized data disclosure and future network intrusion.
Affected Systems
Botslab G980H dash cameras – affected firmware versions are not specified in the advisory.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate impact, but the attacker needs only to be within Bluetooth range. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no publicly documented exploitation. Nevertheless, because the flaw permits unauthenticated access to sensitive configuration data, the risk of local compromise remains high if a malicious actor is physically nearby.
OpenCVE Enrichment