CVE-2026-75558: Botslab G980H Dashcams Use of Hard-coded Cryptographic Key
The Botslab G980H dash camera firmware uses a hard-coded cryptographic key and initialization vector to protect WiFi credentials communicated by the device. An attacker who obtains the protected credential and extracts the cryptographic material from the firmware could recover the WiFi password and gain unauthorized access to the device network.
Affected Software
Event History
Frequently Asked Questions
What must an attacker obtain to recover the WiFi password?
The attacker needs both the protected WiFi credential and the hard-coded cryptographic key and initialization vector extracted from the device firmware. The vulnerability description does not state how the protected credential is obtained.
What access could recovery of the credential provide?
Recovering the WiFi password could allow an attacker to gain unauthorized access to the network used by the device. The described impact is confidentiality loss; integrity and availability impacts are not identified.