CVE-2026-75558

Summary

The Botslab G980H dash camera firmware uses a hard-coded cryptographic key and initialization vector to protect WiFi credentials communicated by the device. An attacker who obtains the protected credential and extracts the cryptographic material from the firmware could recover the WiFi password and gain unauthorized access to the device network.

Affected Software

VendorProductVersion RangeStatus
BotslabG980H30010_QHG980HN5294SysFW+affected
BotslabG980H58_QHG980HMCN5291SysFW+affected

Weaknesses

  • CWE-321: CWE-321 Use of hard-coded cryptographic key

Workarounds

Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information: https://www.botslab.com/pages/about-botslab

References