AI analysis
The Botslab G980H dash camera firmware ships a root account on the device's UART debug interface that requires no password, violating basic authentication requirements for a privileged function. An attacker with physical access can connect to the UART serial console and immediately obtain a root shell on the camera's embedded Linux system. The interface also prints the device's WiFi password to the console during startup, letting the attacker recover the credentials the camera uses for its wireless hotspot/connection. Only owners and operators of the Botslab G980H are affected, and exploitation strictly requires hands-on access to the hardware rather than network reachability. There is no known public proof-of-concept, the flaw is not in the CISA Known Exploited Vulnerabilities catalog, and no exploitation has been reported.
What to do: No patched firmware version is identified in the advisory, so check the CISA ICS advisory and Botslab app for a firmware update and apply it when released. Keep G980H units physically secured (e.g., do not leave them unattended in loaned vehicles or with untrusted parties), since exploitation requires hands-on access to the UART pins. Rotate the WiFi credentials the camera uses if the device has ever been out of your custody, because the password can be read directly off the serial console at boot.
Affected
| Botslab G980H dash camera | — |
Estimated exposure
unknown (consumer dashcam; no public sales or install figures, and exploitation requires physical access) — No active-install counts, sales data, or internet-exposure figures exist for this consumer device, and because the flaw is reachable only through the physical UART interface, it cannot be observed in internet-wide scans.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
The Botslab G980H dash camera firmware contains an authentication vulnerability in the root account exposed through the device's UART interface. The affected account does not require a password before granting access to a privileged system interface, and the interface also displays the device's WiFi password during startup. An unauthenticated attacker with physical access to the device could connect to the UART interface, obtain root privileges, and recover the WiFi password.