View CSAF

Summary

Successful exploitation of these vulnerabilities could allow an attacker to bypass authentication controls, gain unauthorized access to sensitive data and privileged device functionality, modify device configuration, disrupt device operation.

The following versions of Botslab G980H Dashcams are affected:

  • G980H dash cam series 30010_QHG980HN5294SysFW+ (CVE-2026-84399, CVE-2026-82566, CVE-2026-85496, CVE-2026-77967, CVE-2026-88761, CVE-2026-82716, CVE-2026-84403, CVE-2026-75558, CVE-2026-81630, CVE-2026-87118, CVE-2026-82708, CVE-2026-79959, CVE-2026-82585)
  • G980H dash cam series 58_QHG980HMCN5291SysFW+ (CVE-2026-84399, CVE-2026-82566, CVE-2026-85496, CVE-2026-77967, CVE-2026-88761, CVE-2026-88956, CVE-2026-82716, CVE-2026-84403, CVE-2026-75558, CVE-2026-81630, CVE-2026-87118, CVE-2026-82708, CVE-2026-82585)

CVSS

Vendor

Equipment

Vulnerabilities

v3 8.8

Botslab

Botslab G980H Dashcams

Incorrect Authorization, Insufficient Session Expiration, Generation of Predictable Numbers or Identifiers, Authentication Bypass by Capture-replay, Use of Weak Credentials, Missing Authentication for Critical Function, Insertion of Sensitive Information into Log File, Use of Hard-coded Cryptographic Key, Insufficient Verification of Data Authenticity, Out-of-bounds Write, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Use of Hard-coded Credentials, Cleartext Transmission of Sensitive Information

Background

  • Critical Infrastructure Sectors: Transportation Systems
  • Countries/Areas Deployed: Worldwide
  • Company Headquarters Location: China

Vulnerabilities

Expand All +

CVE-2026-84399

The Botslab G980H dash camera firmware contains an authorization vulnerability in its session based command functionality. The product does not sufficiently associate an authenticated session with the client connection that established it, and subsequent privileged operations rely on possession of a valid session identifier without adequately validating the requesting client's authenticated context. An unauthenticated attacker with adjacent network access could potentially use valid session state associated with another client to access privileged functionality.

View CVE Details

Affected Products

Botslab G980H Dashcams

Vendor:

Botslab

Product Version:

Botslab G980H dash cam series: 30010_QHG980HN5294SysFW+, Botslab G980H dash cam series: 58_QHG980HMCN5291SysFW+

Product Status:

known_affected

Remediations

Mitigation

Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information:

https://www.botslab.com/pages/about-botslab

Relevant CWE: CWE-863 Incorrect Authorization

Metrics

CVSS Version

Base Score

Base Severity

Vector String

3.1

8.8

HIGH

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

4.0

8.7

HIGH

CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CVE-2026-82566

The Botslab G980H dash camera firmware contains a session management vulnerability in which authentication state can remain valid after the associated client connection has been terminated or replaced. Under certain connection conditions, a newly established connection can displace an existing client while previously established session state remains active until a separate expiration mechanism invalidates it. An unauthenticated attacker with adjacent network access could potentially take advantage of this residual authentication state to access functionality associated with another client's session.

View CVE Details

Affected Products

Botslab G980H Dashcams

Vendor:

Botslab

Product Version:

Botslab G980H dash cam series: 30010_QHG980HN5294SysFW+, Botslab G980H dash cam series: 58_QHG980HMCN5291SysFW+

Product Status:

known_affected

Remediations

Mitigation

Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information:

https://www.botslab.com/pages/about-botslab

Relevant CWE: CWE-613 Insufficient Session Expiration

Metrics

CVSS Version

Base Score

Base Severity

Vector String

3.1

8.8

HIGH

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

4.0

8.7

HIGH

CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CVE-2026-85496

The Botslab G980H dash camera firmware generates session identifiers using a small sequential value space rather than a suitably unpredictable source. An unauthenticated attacker with adjacent network access and knowledge that an active session exists could potentially determine a valid session identifier and use it to bypass intended authorization controls.

View CVE Details

Affected Products

Botslab G980H Dashcams

Vendor:

Botslab

Product Version:

Botslab G980H dash cam series: 30010_QHG980HN5294SysFW+, Botslab G980H dash cam series: 58_QHG980HMCN5291SysFW+

Product Status:

known_affected

Remediations

Mitigation

Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information:

https://www.botslab.com/pages/about-botslab

Relevant CWE: CWE-340 Generation of Predictable Numbers or Identifiers

Metrics

CVSS Version

Base Score

Base Severity

Vector String

3.1

8.8

HIGH

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

4.0

7.7

HIGH

CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CVE-2026-77967

The Botslab G980H dash camera firmware accepts a reusable authentication value without adequately verifying its freshness or association with the requesting client. An unauthenticated attacker with adjacent network access who captures a valid authentication value could replay it from another client to establish an authenticated session and access privileged device functionality.

View CVE Details

Affected Products

Botslab G980H Dashcams

Vendor:

Botslab

Product Version:

Botslab G980H dash cam series: 30010_QHG980HN5294SysFW+, Botslab G980H dash cam series: 58_QHG980HMCN5291SysFW+

Product Status:

known_affected

Remediations

Mitigation

Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information:

https://www.botslab.com/pages/about-botslab

Relevant CWE: CWE-294 Authentication Bypass by Capture-replay

Metrics

CVSS Version

Base Score

Base Severity

Vector String

3.1

8.1

HIGH

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

4.0

8.6

HIGH

CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

CVE-2026-88761

The Botslab G980H dash camera firmware generates the default WiFi password using predictable device information, portions of which are advertised by the product. An unauthenticated attacker within WiFi range could potentially determine the remaining password characters through limited guessing and gain unauthorized access to the device network.

View CVE Details

Affected Products

Botslab G980H Dashcams

Vendor:

Botslab

Product Version:

Botslab G980H dash cam series: 30010_QHG980HN5294SysFW+, Botslab G980H dash cam series: 58_QHG980HMCN5291SysFW+

Product Status:

known_affected

Remediations

Mitigation

Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information:

https://www.botslab.com/pages/about-botslab

Relevant CWE: CWE-1391 Use of Weak Credentials

Metrics

CVSS Version

Base Score

Base Severity

Vector String

3.1

5.3

MEDIUM

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

4.0

6

MEDIUM

CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

CVE-2026-88956

The Botslab G980H dash camera firmware contains an authentication vulnerability in the root account exposed through the device's UART interface. The affected account does not require a password before granting access to a privileged system interface, and the interface also displays the device's WiFi password during startup. An unauthenticated attacker with physical access to the device could connect to the UART interface, obtain root privileges, and recover the WiFi password.

View CVE Details

Affected Products

Botslab G980H Dashcams

Vendor:

Botslab

Product Version:

Botslab G980H dash cam series: 58_QHG980HMCN5291SysFW+

Product Status:

known_affected

Remediations

Mitigation

Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information:

https://www.botslab.com/pages/about-botslab

Relevant CWE: CWE-306 Missing Authentication for Critical Function

Metrics

CVSS Version

Base Score

Base Severity

Vector String

3.1

6.8

MEDIUM

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

4.0

7

HIGH

CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CVE-2026-82716

The Botslab G980H dash camera firmware includes sensitive configuration information, including WiFi credentials, in diagnostic logs generated during the support process. These logs remain accessible on removable storage after the support operation has completed. An unauthenticated attacker with physical access to the storage media could retrieve the logs and obtain sensitive device information.

View CVE Details

Affected Products

Botslab G980H Dashcams

Vendor:

Botslab

Product Version:

Botslab G980H dash cam series: 30010_QHG980HN5294SysFW+, Botslab G980H dash cam series: 58_QHG980HMCN5291SysFW+

Product Status:

known_affected

Remediations

Mitigation

Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information:

https://www.botslab.com/pages/about-botslab

Relevant CWE: CWE-532 Insertion of Sensitive Information into Log File

Metrics

CVSS Version

Base Score

Base Severity

Vector String

3.1

4.6

MEDIUM

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

4.0

5.1

MEDIUM

CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

CVE-2026-84403

The Botslab G980H dash camera firmware does not require authenticated pairing or client binding before permitting access to Bluetooth Low Energy communications and GATT characteristics. An unauthenticated attacker within Bluetooth range could intercept or directly retrieve sensitive device information, including device identifiers, firmware information, and protected WiFi credentials.

View CVE Details

Affected Products

Botslab G980H Dashcams

Vendor:

Botslab

Product Version:

Botslab G980H dash cam series: 30010_QHG980HN5294SysFW+, Botslab G980H dash cam series: 58_QHG980HMCN5291SysFW+

Product Status:

known_affected

Remediations

Mitigation

Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information:

https://www.botslab.com/pages/about-botslab

Relevant CWE: CWE-306 Missing Authentication for Critical Function

Metrics

CVSS Version

Base Score

Base Severity

Vector String

3.1

6.2

MEDIUM

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

4.0

6.9

MEDIUM

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

CVE-2026-75558

The Botslab G980H dash camera firmware uses a hard-coded cryptographic key and initialization vector to protect WiFi credentials communicated by the device. An attacker who obtains the protected credential and extracts the cryptographic material from the firmware could recover the WiFi password and gain unauthorized access to the device network.

View CVE Details

Affected Products

Botslab G980H Dashcams

Vendor:

Botslab

Product Version:

Botslab G980H dash cam series: 30010_QHG980HN5294SysFW+, Botslab G980H dash cam series: 58_QHG980HMCN5291SysFW+

Product Status:

known_affected

Remediations

Mitigation

Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information:

https://www.botslab.com/pages/about-botslab

Relevant CWE: CWE-321 Use of Hard-coded Cryptographic Key

Metrics

CVSS Version

Base Score

Base Severity

Vector String

3.1

5.3

MEDIUM

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

4.0

6

MEDIUM

CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

CVE-2026-81630

The Botslab G980H dash camera firmware does not adequately verify the authenticity of firmware updates. The update process retrieves firmware through an unprotected connection and relies on an integrity value supplied with the firmware instead of a trusted cryptographic signature. A suitably positioned attacker who intercepts a firmware download, or an authenticated attacker who submits a crafted update, could install modified firmware and execute unauthorized code on the device.

View CVE Details

Affected Products

Botslab G980H Dashcams

Vendor:

Botslab

Product Version:

Botslab G980H dash cam series: 30010_QHG980HN5294SysFW+, Botslab G980H dash cam series: 58_QHG980HMCN5291SysFW+

Product Status:

known_affected

Remediations

Mitigation

Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information:

https://www.botslab.com/pages/about-botslab

Relevant CWE: CWE-345 Insufficient Verification of Data Authenticity

Metrics

CVSS Version

Base Score

Base Severity

Vector String

3.1

8.1

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

4.0

9.2

CRITICAL

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CVE-2026-87118

The Botslab G980H dash camera firmware contains an out of bounds write vulnerability in its command processing functionality. An authenticated attacker with adjacent network access could submit crafted command data that corrupts memory, potentially disrupting authentication state or causing the affected process to terminate and the device to restart, resulting in a temporary denial of service.

View CVE Details

Affected Products

Botslab G980H Dashcams

Vendor:

Botslab

Product Version:

Botslab G980H dash cam series: 30010_QHG980HN5294SysFW+, Botslab G980H dash cam series: 58_QHG980HMCN5291SysFW+

Product Status:

known_affected

Remediations

Mitigation

Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information:

https://www.botslab.com/pages/about-botslab

Relevant CWE: CWE-787 Out-of-bounds Write

Metrics

CVSS Version

Base Score

Base Severity

Vector String

3.1

5.7

MEDIUM

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

4.0

6.9

MEDIUM

CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

CVE-2026-82708

The Botslab G980H dash camera firmware contains a path traversal vulnerability in its HTTP server. An attacker with access to the device's WiFi network could submit a crafted request to access files within the device's removable storage that were not intended to be directly accessible through the web server. Exposed files could include recordings, images, diagnostic logs, or firmware files.

View CVE Details

Affected Products

Botslab G980H Dashcams

Vendor:

Botslab

Product Version:

Botslab G980H dash cam series: 30010_QHG980HN5294SysFW+, Botslab G980H dash cam series: 58_QHG980HMCN5291SysFW+

Product Status:

known_affected

Remediations

Mitigation

Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information:

https://www.botslab.com/pages/about-botslab

Relevant CWE: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Metrics

CVSS Version

Base Score

Base Severity

Vector String

3.1

6.5

MEDIUM

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

4.0

7.1

HIGH

CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

CVE-2026-79959

The Botslab G980H dash camera firmware contains a hard-coded root account password that cannot be changed by the user. An attacker who obtains the firmware or has physical access to the device could recover the credential and use it to obtain root access through the UART interface.

View CVE Details

Affected Products

Botslab G980H Dashcams

Vendor:

Botslab

Product Version:

Botslab G980H dash cam series: 30010_QHG980HN5294SysFW+

Product Status:

known_affected

Remediations

Mitigation

Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information:

https://www.botslab.com/pages/about-botslab

Relevant CWE: CWE-798 Use of Hard-coded Credentials

Metrics

CVSS Version

Base Score

Base Severity

Vector String

3.1

6.8

MEDIUM

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

4.0

7

HIGH

CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CVE-2026-82585

The Botslab G980H dash camera firmware transmits sensitive information over unencrypted HTTP and RTSP connections. An attacker capable of intercepting communications on the device's WiFi network could obtain stored recordings, live video, location information, images, diagnostic logs, or other sensitive information exchanged between the device and its mobile application.

View CVE Details

Affected Products

Botslab G980H Dashcams

Vendor:

Botslab

Product Version:

Botslab G980H dash cam series: 30010_QHG980HN5294SysFW+, Botslab G980H dash cam series: 58_QHG980HMCN5291SysFW+

Product Status:

known_affected

Remediations

Mitigation

Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information:

https://www.botslab.com/pages/about-botslab

Relevant CWE: CWE-319 Cleartext Transmission of Sensitive Information

Metrics

CVSS Version

Base Score

Base Severity

Vector String

3.1

6.5

MEDIUM

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

4.0

7.1

HIGH

CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Acknowledgments

  • Julian of Software Secured reported these vulnerabilities to CISA.

Legal Notice and Terms of Use

This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).

Recommended Practices

CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.

  • Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.
  • Locate control system networks and remote devices behind firewalls and isolating them from business networks.
  • When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.

CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.

CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.

CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.

Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.

Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.

CISA also recommends users take the following measures to protect themselves from social engineering attacks:

  • Do not click web links or open attachments in unsolicited email messages.
  • Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.
  • Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.

No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.

Revision History

  • Initial Release Date: 2026-09-24

Date

Revision

Summary

2026-09-24

1

Initial Publication

Legal Notice and Terms of Use