Impact
The Botslab G980H dash camera firmware contains an authentication flaw that allows an attacker with physical access to connect to the UART interface and obtain root privileges without providing a password. The same interface displays the device’s WiFi password during startup, giving the attacker lower‑level network access as well. This lack of authentication is a clear enforcement issue (CWE‑306) that enables full control over the device, including firmware tampering, data exfiltration, and unauthorized command execution.
Affected Systems
Botslab G980H dash cameras. Firmware versions are unspecified; the vulnerability applies to all units that expose a root account through the UART port, regardless of firmware revision. No specific version details are provided by the CNA.
Risk and Exploitability
The assigned CVSS score of 7 indicates high severity. EPSS data is not available, so the exploitation probability cannot be quantified precisely, but the presence of an unprotected UART port means that a local attacker can readily craft the exploit. The issue is not listed in CISA’s KEV catalog, and no publicly known exploit has been reported. The most likely attack vector is a physical attacker who can attach to the UART interface during maintenance or supply chain handling.
OpenCVE Enrichment