Description
The Botslab G980H dash camera firmware generates the default WiFi password using predictable device information, portions of which are advertised by the product. An unauthenticated attacker within WiFi range could potentially determine the remaining password characters through limited guessing and gain unauthorized access to the device network.
Published: 2026-09-24
Score: 6 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized access to device network
Action: Assess Impact
AI Analysis

Impact

The firmware of the Botslab G980H dash camera constructs the default WiFi password from predictable device identifiers that are exposed by the product. An attacker who can listen to the local wireless network may guess the remaining characters with limited attempts, thereby obtaining the full password. Once the password is discovered, the attacker can connect to the camera’s local network, potentially gain control of the device, eavesdrop on video streams, or modify configuration settings.

Affected Systems

Botslab G980H dash cameras released under firmware versions that generate passwords from device metadata. All units in operation that have not been updated to a version with random or user‑defined passwords are affected.

Risk and Exploitability

The CVSS score of 6 indicates moderate severity and the EPSS score is not available, so the current certainty of exploitation is unknown. The vulnerability is not listed in CISA KEV, yet an unauthenticated attacker within WiFi range can try a small number of password guesses to complete the password, making exploitation feasible with minimal effort in a local environment.

Generated by OpenCVE AI on September 25, 2026 at 03:13 UTC.

Remediation

Vendor Workaround

Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information: https://www.botslab.com/pages/about-botslab


OpenCVE Recommended Actions

  • Immediately change the default WiFi password to a strong, random value that does not rely on device metadata.
  • Configure the dashcam to use WPA2/WPA3 encryption and disable any open or auto‑connect options.
  • Monitor the vendor’s advisories and wait for a firmware update that eliminates the predictable password generation; apply it when released or contact Botslab for guidance.

Generated by OpenCVE AI on September 25, 2026 at 03:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description The Botslab G980H dash camera firmware generates the default WiFi password using predictable device information, portions of which are advertised by the product. An unauthenticated attacker within WiFi range could potentially determine the remaining password characters through limited guessing and gain unauthorized access to the device network.
Title Botslab G980H Dashcams Use of Weak Credentials
Weaknesses CWE-1391
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-09-24T19:55:34.395Z

Reserved: 2026-09-10T15:31:03.078Z

Link: CVE-2026-88761

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-24T20:17:33.643

Modified: 2026-09-24T21:25:27.050

Link: CVE-2026-88761

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-25T03:15:14Z

Weaknesses