Impact
The firmware of the Botslab G980H dash camera constructs the default WiFi password from predictable device identifiers that are exposed by the product. An attacker who can listen to the local wireless network may guess the remaining characters with limited attempts, thereby obtaining the full password. Once the password is discovered, the attacker can connect to the camera’s local network, potentially gain control of the device, eavesdrop on video streams, or modify configuration settings.
Affected Systems
Botslab G980H dash cameras released under firmware versions that generate passwords from device metadata. All units in operation that have not been updated to a version with random or user‑defined passwords are affected.
Risk and Exploitability
The CVSS score of 6 indicates moderate severity and the EPSS score is not available, so the current certainty of exploitation is unknown. The vulnerability is not listed in CISA KEV, yet an unauthenticated attacker within WiFi range can try a small number of password guesses to complete the password, making exploitation feasible with minimal effort in a local environment.
OpenCVE Enrichment