CVE-2026-75558: Botslab G980H Dashcams Use of Hard-coded Cryptographic Key

Published Sep 24, 2026
·
Updated

The Botslab G980H dash camera firmware uses a hard-coded cryptographic key and initialization vector to protect WiFi credentials communicated by the device. An attacker who obtains the protected credential and extracts the cryptographic material from the firmware could recover the WiFi password and gain unauthorized access to the device network.

Affected Software

1 affected component
Botslab G980H Dashcams

Event History

Sep 24, 2026
CVE Published
via MITRE·08:11 PM
Data Sourced
via MITRE·08:11 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What must an attacker obtain to recover the WiFi password?

The attacker needs both the protected WiFi credential and the hard-coded cryptographic key and initialization vector extracted from the device firmware. The vulnerability description does not state how the protected credential is obtained.

2

What access could recovery of the credential provide?

Recovering the WiFi password could allow an attacker to gain unauthorized access to the network used by the device. The described impact is confidentiality loss; integrity and availability impacts are not identified.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203