Impact
The firmware of the Botslab G980H dash camera includes a pathname traversal flaw in its HTTP server, allowing an attacker to gain unauthorized access to files stored on the device’s removable media. Exposed files may contain recorded video, images, diagnostic logs, or firmware binaries, thereby compromising confidentiality and potentially allowing further exploitation of the device. The weakness is classified as CWE-22, a limitation of pathname control vulnerability.
Affected Systems
The vulnerability affects all models of the Botslab G980H dash cam. No specific firmware version numbers are provided in the advisory, so any installed firmware on a G980H device is considered at risk.
Risk and Exploitability
The CVSS base score of 7.1 indicates a high severity attack that could lead to significant data exposure. The EPSS score is not available, so the current likelihood of exploitation is unknown, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Access to the device is inferred to require proximity to or compromise of the device’s WiFi network, making physical or local network compromise the most probable attack vector. Attacks would involve crafting a special HTTP request to the dash cam’s web interface and leveraging the path traversal to read files from removable storage.
OpenCVE Enrichment