Description
The Botslab G980H dash camera firmware contains a session management vulnerability in which authentication state can remain valid after the associated client connection has been terminated or replaced. Under certain connection conditions, a newly established connection can displace an existing client while previously established session state remains active until a separate expiration mechanism invalidates it. An unauthenticated attacker with adjacent network access could potentially take advantage of this residual authentication state to access functionality associated with another client's session.
Published: 2026-09-24
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized access to dashcam functions via residual authentication state.
Action: Patch
AI Analysis

Impact

The G980H dash camera firmware has a session management flaw that allows authentication state to persist after a client disconnects or is replaced. Under certain connection patterns, a new connection can overwrite an existing client while the old session remains valid until it is explicitly expired. This residual session can be used by an unauthenticated attacker with adjacent network access to access the functions associated with the other user's session. The flaw represents a classic session information leakage (CWE-613).

Affected Systems

Botslab G980H dash cameras. The vulnerability is present in the firmware released for the G980H model. No detailed version list is supplied, so the issue applies to all current firmware releases of this device until a fix is issued.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity and the EPSS score is not available, so the likelihood of exploitation cannot be quantified precisely, but the lack of a response from Botslab suggests no publicly available patches. The KEV catalog does not list this vulnerability, implying no confirmed exploitation yet, yet the vulnerability is still highly actionable. The attack is likely to occur on an adjacent local network where the attacker can open a fresh connection to the device; no elevated privileges or special configuration are required beyond network proximity.

Generated by OpenCVE AI on September 25, 2026 at 03:50 UTC.

Remediation

Vendor Workaround

Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information: https://www.botslab.com/pages/about-botslab


OpenCVE Recommended Actions

  • Apply the latest firmware update from Botslab that resolves the session expiration flaw.
  • If no update is available, isolate the dash camera from other network segments using VLANs or ACLs to limit its exposure to adjacent hosts.
  • Implement network monitoring and set alerts for repeated authentication sessions that do not terminate normally, to detect and contain unauthorized access attempts.

Generated by OpenCVE AI on September 25, 2026 at 03:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 25 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Botslab
Botslab g980h
Vendors & Products Botslab
Botslab g980h

Thu, 24 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 24 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Description The Botslab G980H dash camera firmware contains a session management vulnerability in which authentication state can remain valid after the associated client connection has been terminated or replaced. Under certain connection conditions, a newly established connection can displace an existing client while previously established session state remains active until a separate expiration mechanism invalidates it. An unauthenticated attacker with adjacent network access could potentially take advantage of this residual authentication state to access functionality associated with another client's session.
Title Botslab G980H Dashcams Insufficient session expiration
Weaknesses CWE-613
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-09-24T19:37:00.841Z

Reserved: 2026-09-10T15:31:03.065Z

Link: CVE-2026-82566

cve-icon Vulnrichment

Updated: 2026-09-24T19:36:56.192Z

cve-icon NVD

Status : Deferred

Published: 2026-09-24T20:17:32.503

Modified: 2026-09-24T21:25:27.050

Link: CVE-2026-82566

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-25T14:15:42Z

Weaknesses
  • CWE-613

    Insufficient Session Expiration