---
id: CVE-2026-75558
title: >-
  The Botslab G980H dash camera firmware uses a hard-coded cryptographic key and
  initialization vector to protect WiFi credentials communicated by the device
summary: >-
  The Botslab G980H dash camera firmware uses a hard-coded cryptographic key and
  initialization vector to protect WiFi credentials communicated by the device.
  An attacker who obtains the protected credential and extracts the
  cryptographic …
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-321
vendor: Botslab
product: G980H
affected:
  - G980H 30010_QHG980HN5294SysFW+
  - G980H 58_QHG980HMCN5291SysFW+
published: '2026-09-24'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T21:25:27.050'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-75558'
references:
  - url: >-
      https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-267-01.json
    label: ics-cert@hq.dhs.gov
  - url: 'https://www.botslab.com/pages/about-botslab'
    label: ics-cert@hq.dhs.gov
  - url: 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-267-01'
    label: ics-cert@hq.dhs.gov
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-24T20:51:40.354Z'
---

## Overview

The Botslab G980H dash camera firmware uses a hard-coded cryptographic key and initialization vector to protect WiFi credentials communicated by the device. An attacker who obtains the protected credential and extracts the cryptographic material from the firmware could recover the WiFi password and gain unauthorized access to the device network.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
