Description
The Botslab G980H dash camera firmware accepts a reusable authentication value without adequately verifying its freshness or association with the requesting client. An unauthenticated attacker with adjacent network access who captures a valid authentication value could replay it from another client to establish an authenticated session and access privileged device functionality.
Published: 2026-09-24
Score: 8.6 High
EPSS: n/a
KEV: No
Impact: Authentication Bypass exposing privileged device functions
Action: Patch or Mitigate
AI Analysis

Impact

The firmware of Botslab G980H dashcams accepts a reusable authentication value without properly checking its freshness or client association. An attacker who can connect to the same local network as the device can capture a valid authentication token and replay it from another client, thereby establishing an authenticated session and gaining access to privileged functionalities without performing initial authentication.

Affected Systems

Botslab G980H dashcams are affected. No specific firmware versions are listed, so all current releases of the G980H product line should be treated as vulnerable.

Risk and Exploitability

The vulnerability carries a CVSS score of 8.6, indicating a high severity. EPSS data is not available, and the flaw has not yet been listed in CISA KEV. Based on the description, the likely attack vector is a local or adjacent network attacker who captures authentication traffic. Once a valid token is obtained, replaying it is straightforward, allowing the attacker to bypass authentication and control the device.

Generated by OpenCVE AI on September 25, 2026 at 03:13 UTC.

Remediation

Vendor Workaround

Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information: https://www.botslab.com/pages/about-botslab


OpenCVE Recommended Actions

  • Contact Botslab to request remediation guidance or a future firmware update.
  • Isolate G980H dashcams by segmenting them from unsecured or adjacent network traffic to prevent an attacker from capturing authentication values.
  • Configure local or firewall rules to disable or restrict remote authentication channels until a vendor patch is available.

Generated by OpenCVE AI on September 25, 2026 at 03:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Description The Botslab G980H dash camera firmware accepts a reusable authentication value without adequately verifying its freshness or association with the requesting client. An unauthenticated attacker with adjacent network access who captures a valid authentication value could replay it from another client to establish an authenticated session and access privileged device functionality.
Title Botslab G980H Dashcams Authentication Bypass by Capture-replay
Weaknesses CWE-294
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-09-24T19:51:27.318Z

Reserved: 2026-09-10T15:31:03.075Z

Link: CVE-2026-77967

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-24T20:17:30.227

Modified: 2026-09-24T21:25:27.050

Link: CVE-2026-77967

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-25T03:15:14Z

Weaknesses
  • CWE-294

    Authentication Bypass by Capture-replay