Skip to finding
important · Bluetooth

A Botslab G980H exposes protected Wi-Fi credential material to an unpaired BLE client.

Affects

Botslab G980H dash cameras, embedded in-vehicle recording devices with BLE provisioning and a local Wi-Fi network.

The newly understood link is in the firmware: a hard-coded key and initialization vector provide a provisional path from the BLE-readable credential to the Wi-Fi password.

Detail and 1 source

We do not have public evidence of end-to-end decryption using a credential captured from a named shipping unit, and plaintext recovery also requires the matching firmware image.

Chain to watch
Capture the protected credential from a shipping G980H over an unpaired BLE connection.→↓Extract the key and initialization vector from the matching firmware build.→↓Decrypt the credential and verify that the recovered password joins the dashcam network.→↓The BLE read and firmware constants have not been joined in a public end-to-end reproduction on a named shipping unit.
Unverified chainAcquire a matching firmware build, capture the BLE credential, and test whether the recovered plaintext joins the camera network.
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Monday, September 28, 2026