---
cve: "CVE-2026-75558"
severity: "MEDIUM"
cvss: 6.0
epss: "3.4%"
vendor: "Botslab"
kev: false
exploited: false
published: "2026-09-24 21:18:36"
tags: [cve, security, medium]
source: tsecurity.de CVE-Dossier
exported: "2026-09-25T01:17:29+02:00"
---

# CVE-2026-75558

> 6.0 MEDIUM · 🧪 PoC

## Beschreibung

The Botslab G980H dash camera firmware uses a hard-coded cryptographic key and initialization vector to protect WiFi credentials communicated by the device. An attacker who obtains the protected credential and extracts the cryptographic material from the firmware could recover the WiFi password and gain unauthorized access to the device network.

## CVSS-Vektor

```
CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Benachbart | warn |
| AC Komplexität | Hoch | good |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |

## Referenzen

- <https://www.botslab.com/pages/about-botslab>
- <https://www.cisa.gov/news-events/ics-advisories/icsa-26-267-01>
- <https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-267-01.json>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-75558) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
