Impact
The firmware of Botslab G980H dashcams accepts a reusable authentication value without properly checking its freshness or client association. An attacker who can connect to the same local network as the device can capture a valid authentication token and replay it from another client, thereby establishing an authenticated session and gaining access to privileged functionalities without performing initial authentication.
Affected Systems
Botslab G980H dashcams are affected. No specific firmware versions are listed, so all current releases of the G980H product line should be treated as vulnerable.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.6, indicating a high severity. EPSS data is not available, and the flaw has not yet been listed in CISA KEV. Based on the description, the likely attack vector is a local or adjacent network attacker who captures authentication traffic. Once a valid token is obtained, replaying it is straightforward, allowing the attacker to bypass authentication and control the device.
OpenCVE Enrichment