AI analysis
The Botslab G980H dash camera firmware derives its default WiFi password from predictable device information, some of which the product itself advertises (for example identifiers printed on the unit or reflected in broadcast identifiers). Because the unknown portion of the password is small, an unauthenticated attacker within WiFi range can recover the remaining characters through limited guessing and join the camera's wireless network. This gives the attacker a foothold on the camera's local network, where they could potentially reach its live video stream, recordings, and configuration interfaces. Anyone operating a G980H that still uses the factory-default WiFi credentials is affected. There is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and no exploitation in the wild has been reported.
What to do: Replace the default WiFi password with a long, random, unique password via the Botslab app immediately — the flaw is only exploitable while factory credentials are in use. Check the vendor's app and support site for G980H firmware updates and apply any release that changes password generation. Keep the camera's WiFi hotspot disabled when not configuring it, and avoid pairing or operating the camera in shared RF range such as public parking areas.
Affected
| Botslab G980H Dash Camera | All firmware versions (advisory does not specify version ranges or a fixed version) |
Estimated exposure
unknown — no public sales or deployment data; plausibly a fleet in the tens of thousands of units for a single consumer dashcam SKU, but this is speculation — Botslab publishes no unit sales figures and dashcams are WiFi-adjacent rather than internet-exposed, so neither market-share data nor internet-wide scans provide a basis for sizing the installed base.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
The Botslab G980H dash camera firmware generates the default WiFi password using predictable device information, portions of which are advertised by the product. An unauthenticated attacker within WiFi range could potentially determine the remaining password characters through limited guessing and gain unauthorized access to the device network.