Impact
Botslab's G980H dash camera firmware omits proper verification of firmware authenticity. During the update process the camera downloads new firmware over an unprotected connection and validates only a supplied integrity value rather than a trusted cryptographic signature. A malicious actor positioned to intercept the firmware download, or an authorized user who submits a crafted update, can therefore deliver malicious firmware that will be installed on the device, giving the attacker the ability to execute arbitrary code. This flaw aligns with CWE‑345, describing insufficient verification of data authenticity.
Affected Systems
The vulnerability affects all Botslab G980H dash cameras that use the current firmware update mechanism. No specific firmware version list was provided, so any device relying on the described update process is potentially impacted. Users should assume that any G980H model present in their environment is at risk until a signed‑firmware update is available from Botslab.
Risk and Exploitability
The CVSS score of 9.2 indicates a severe risk, and the lack of an EPSS score makes the exact likelihood of exploitation uncertain, but the vulnerability is demonstrable and could be weaponized by attackers with network access or administrative credentials. Because the flaw relies on an unprotected update channel, an attacker with physical proximity or network connectivity to the dash cam could capture or forge firmware packets. The flaw is not listed in CISA's KEV catalog, but the severity suggests that organizations reliant on these devices should treat it with high caution and pursue mitigation as soon as possible.
OpenCVE Enrichment