Back to Feed
VulnerabilitiesSep 24, 2026

Botslab G980H Dashcams

Botslab G980H dashcams have multiple critical vulnerabilities allowing unauthorized access.

Summary

Multiple critical vulnerabilities have been discovered in Botslab G980H dashcams, affecting firmware versions 30010_QHG980HN5294SysFW+ and 58_QHG980HMCN5291SysFW+. These flaws could allow attackers to bypass authentication, gain unauthorized access to data and device functions, modify configurations, and disrupt operations. Botslab has not yet responded to requests for mitigation.

Full text

ICS Advisory Botslab G980H Dashcams Release DateSeptember 24, 2026 Alert CodeICSA-26-267-01 Related topics: Industrial Control System Vulnerabilities , Industrial Control Systems View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to bypass authentication controls, gain unauthorized access to sensitive data and privileged device functionality, modify device configuration, disrupt device operation. The following versions of Botslab G980H Dashcams are affected: G980H dash cam series 30010_QHG980HN5294SysFW+ (CVE-2026-84399, CVE-2026-82566, CVE-2026-85496, CVE-2026-77967, CVE-2026-88761, CVE-2026-82716, CVE-2026-84403, CVE-2026-75558, CVE-2026-81630, CVE-2026-87118, CVE-2026-82708, CVE-2026-79959, CVE-2026-82585) G980H dash cam series 58_QHG980HMCN5291SysFW+ (CVE-2026-84399, CVE-2026-82566, CVE-2026-85496, CVE-2026-77967, CVE-2026-88761, CVE-2026-88956, CVE-2026-82716, CVE-2026-84403, CVE-2026-75558, CVE-2026-81630, CVE-2026-87118, CVE-2026-82708, CVE-2026-82585) CVSS Vendor Equipment Vulnerabilities v3 8.8 Botslab Botslab G980H Dashcams Incorrect Authorization, Insufficient Session Expiration, Generation of Predictable Numbers or Identifiers, Authentication Bypass by Capture-replay, Use of Weak Credentials, Missing Authentication for Critical Function, Insertion of Sensitive Information into Log File, Use of Hard-coded Cryptographic Key, Insufficient Verification of Data Authenticity, Out-of-bounds Write, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Use of Hard-coded Credentials, Cleartext Transmission of Sensitive Information Background Critical Infrastructure Sectors: Transportation Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: China Vulnerabilities Expand All + CVE-2026-84399 The Botslab G980H dash camera firmware contains an authorization vulnerability in its session based command functionality. The product does not sufficiently associate an authenticated session with the client connection that established it, and subsequent privileged operations rely on possession of a valid session identifier without adequately validating the requesting client's authenticated context. An unauthenticated attacker with adjacent network access could potentially use valid session state associated with another client to access privileged functionality. View CVE Details Affected Products Botslab G980H Dashcams Vendor:Botslab Product Version:Botslab G980H dash cam series: 30010_QHG980HN5294SysFW+, Botslab G980H dash cam series: 58_QHG980HMCN5291SysFW+ Product Status:known_affected Remediations MitigationBotslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information: https://www.botslab.com/pages/about-botslab Relevant CWE: CWE-863 Incorrect Authorization Metrics CVSS Version Base Score Base Severity Vector String 3.1 8.8 HIGH CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 4.0 8.7 HIGH CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVE-2026-82566 The Botslab G980H dash camera firmware contains a session management vulnerability in which authentication state can remain valid after the associated client connection has been terminated or replaced. Under certain connection conditions, a newly established connection can displace an existing client while previously established session state remains active until a separate expiration mechanism invalidates it. An unauthenticated attacker with adjacent network access could potentially take advantage of this residual authentication state to access functionality associated with another client's session. View CVE Details Affected Products Botslab G980H Dashcams Vendor:Botslab Product Version:Botslab G980H dash cam series: 30010_QHG980HN5294SysFW+, Botslab G980H dash cam series: 58_QHG980HMCN5291SysFW+ Product Status:known_affected Remediations MitigationBotslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information: https://www.botslab.com/pages/about-botslab Relevant CWE: CWE-613 Insufficient Session Expiration Metrics CVSS Version Base Score Base Severity Vector String 3.1 8.8 HIGH CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 4.0 8.7 HIGH CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVE-2026-85496 The Botslab G980H dash camera firmware generates session identifiers using a small sequential value space rather than a suitably unpredictable source. An unauthenticated attacker with adjacent network access and knowledge that an active session exists could potentially determine a valid session identifier and use it to bypass intended authorization controls. View CVE Details Affected Products Botslab G980H Dashcams Vendor:Botslab Product Version:Botslab G980H dash cam series: 30010_QHG980HN5294SysFW+, Botslab G980H dash cam series: 58_QHG980HMCN5291SysFW+ Product Status:known_affected Remediations MitigationBotslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information: https://www.botslab.com/pages/about-botslab Relevant CWE: CWE-340 Generation of Predictable Numbers or Identifiers Metrics CVSS Version Base Score Base Severity Vector String 3.1 8.8 HIGH CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 4.0 7.7 HIGH CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVE-2026-77967 The Botslab G980H dash camera firmware accepts a reusable authentication value without adequately verifying its freshness or association with the requesting client. An unauthenticated attacker with adjacent network access who captures a valid authentication value could replay it from another client to establish an authenticated session and access privileged device functionality. View CVE Details Affected Products Botslab G980H Dashcams Vendor:Botslab Product Version:Botslab G980H dash cam series: 30010_QHG980HN5294SysFW+, Botslab G980H dash cam series: 58_QHG980HMCN5291SysFW+ Product Status:known_affected Remediations MitigationBotslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information: https://www.botslab.com/pages/about-botslab Relevant CWE: CWE-294 Authentication Bypass by Capture-replay Metrics CVSS Version Base Score Base Severity Vector String 3.1 8.1 HIGH CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N 4.0 8.6 HIGH CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N CVE-2026-88761 The Botslab G980H dash camera firmware generates the default WiFi password using predictable device information, portions of which are advertised by the product. An unauthenticated attacker within WiFi range could potentially determine the remaining password characters through limited guessing and gain unauthorized access to the device network. View CVE Details Affected Products Botslab G980H Dashcams Vendor:Botslab Product Version:Botslab G980H dash cam series: 30010_QHG980HN5294SysFW+, Botslab G980H dash cam series: 58_QHG980HMCN5291SysFW+ Product Status:known_affected Remediations MitigationBotslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information: https://www.botslab.com/pages/about-botslab Relevant CWE: CWE-1391 Use of Weak Credentials Metrics CVSS Version Base Score Base Severity Vector String 3.1 5.3 MEDIUM CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N 4.0 6 MEDIUM CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVE-2026-88956 The Botslab G980H dash camera firmware contains an authentication vulnerability in the root account exposed through the device's UART interface. Th

Indicators of Compromise

  • cve — CVE-2026-84399
  • cve — CVE-2026-82566
  • cve — CVE-2026-85496
  • cve — CVE-2026-77967
  • cve — CVE-2026-88761
  • cve — CVE-2026-88956
  • cve — CVE-2026-82716
  • cve — CVE-2026-84403
  • cve — CVE-2026-75558
  • cve — CVE-2026-81630
  • cve — CVE-2026-87118
  • cve — CVE-2026-82708
  • cve — CVE-2026-79959
  • cve — CVE-2026-82585

Entities

G980H Dashcams (product)Botslab (vendor)