Impact
The G980H dash camera firmware has a session management flaw that allows authentication state to persist after a client disconnects or is replaced. Under certain connection patterns, a new connection can overwrite an existing client while the old session remains valid until it is explicitly expired. This residual session can be used by an unauthenticated attacker with adjacent network access to access the functions associated with the other user's session. The flaw represents a classic session information leakage (CWE-613).
Affected Systems
Botslab G980H dash cameras. The vulnerability is present in the firmware released for the G980H model. No detailed version list is supplied, so the issue applies to all current firmware releases of this device until a fix is issued.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity and the EPSS score is not available, so the likelihood of exploitation cannot be quantified precisely, but the lack of a response from Botslab suggests no publicly available patches. The KEV catalog does not list this vulnerability, implying no confirmed exploitation yet, yet the vulnerability is still highly actionable. The attack is likely to occur on an adjacent local network where the attacker can open a fresh connection to the device; no elevated privileges or special configuration are required beyond network proximity.
OpenCVE Enrichment