Description
The Botslab G980H dash camera firmware does not adequately verify the authenticity of firmware updates. The update process retrieves firmware through an unprotected connection and relies on an integrity value supplied with the firmware instead of a trusted cryptographic signature. A suitably positioned attacker who intercepts a firmware download, or an authenticated attacker who submits a crafted update, could install modified firmware and execute unauthorized code on the device.
Published: 2026-09-24
Score: 9.2 Critical
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Contact Vendor
AI Analysis

Impact

Botslab's G980H dash camera firmware omits proper verification of firmware authenticity. During the update process the camera downloads new firmware over an unprotected connection and validates only a supplied integrity value rather than a trusted cryptographic signature. A malicious actor positioned to intercept the firmware download, or an authorized user who submits a crafted update, can therefore deliver malicious firmware that will be installed on the device, giving the attacker the ability to execute arbitrary code. This flaw aligns with CWE‑345, describing insufficient verification of data authenticity.

Affected Systems

The vulnerability affects all Botslab G980H dash cameras that use the current firmware update mechanism. No specific firmware version list was provided, so any device relying on the described update process is potentially impacted. Users should assume that any G980H model present in their environment is at risk until a signed‑firmware update is available from Botslab.

Risk and Exploitability

The CVSS score of 9.2 indicates a severe risk, and the lack of an EPSS score makes the exact likelihood of exploitation uncertain, but the vulnerability is demonstrable and could be weaponized by attackers with network access or administrative credentials. Because the flaw relies on an unprotected update channel, an attacker with physical proximity or network connectivity to the dash cam could capture or forge firmware packets. The flaw is not listed in CISA's KEV catalog, but the severity suggests that organizations reliant on these devices should treat it with high caution and pursue mitigation as soon as possible.

Generated by OpenCVE AI on September 25, 2026 at 03:10 UTC.

Remediation

Vendor Workaround

Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information: https://www.botslab.com/pages/about-botslab


OpenCVE Recommended Actions

  • Contact Botslab for a firmware revision that implements cryptographic signature verification
  • Restrict network traffic to the dash camera’s firmware update service using firewall rules or VLAN segmentation
  • Disable the automatic firmware update capability or block unauthenticated update requests until a validated firmware is installed

Generated by OpenCVE AI on September 25, 2026 at 03:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description The Botslab G980H dash camera firmware does not adequately verify the authenticity of firmware updates. The update process retrieves firmware through an unprotected connection and relies on an integrity value supplied with the firmware instead of a trusted cryptographic signature. A suitably positioned attacker who intercepts a firmware download, or an authenticated attacker who submits a crafted update, could install modified firmware and execute unauthorized code on the device.
Title Botslab G980H Dashcams Insufficient Verification of Data Authenticity
Weaknesses CWE-345
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-09-24T20:14:42.513Z

Reserved: 2026-09-10T15:25:29.830Z

Link: CVE-2026-81630

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-24T21:18:48.737

Modified: 2026-09-24T21:25:27.050

Link: CVE-2026-81630

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-25T03:15:14Z

Weaknesses
  • CWE-345

    Insufficient Verification of Data Authenticity