Description
The Botslab G980H dash camera firmware contains a path traversal vulnerability in its HTTP server. An attacker with access to the device's WiFi network could submit a crafted request to access files within the device's removable storage that were not intended to be directly accessible through the web server. Exposed files could include recordings, images, diagnostic logs, or firmware files.
Published: 2026-09-24
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Remote Access to Sensitive Files
Action: Contact Vendor
AI Analysis

Impact

The firmware of the Botslab G980H dash camera includes a pathname traversal flaw in its HTTP server, allowing an attacker to gain unauthorized access to files stored on the device’s removable media. Exposed files may contain recorded video, images, diagnostic logs, or firmware binaries, thereby compromising confidentiality and potentially allowing further exploitation of the device. The weakness is classified as CWE-22, a limitation of pathname control vulnerability.

Affected Systems

The vulnerability affects all models of the Botslab G980H dash cam. No specific firmware version numbers are provided in the advisory, so any installed firmware on a G980H device is considered at risk.

Risk and Exploitability

The CVSS base score of 7.1 indicates a high severity attack that could lead to significant data exposure. The EPSS score is not available, so the current likelihood of exploitation is unknown, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Access to the device is inferred to require proximity to or compromise of the device’s WiFi network, making physical or local network compromise the most probable attack vector. Attacks would involve crafting a special HTTP request to the dash cam’s web interface and leveraging the path traversal to read files from removable storage.

Generated by OpenCVE AI on September 25, 2026 at 03:08 UTC.

Remediation

Vendor Workaround

Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information: https://www.botslab.com/pages/about-botslab


OpenCVE Recommended Actions

  • Contact Botslab to obtain a patch or firmware update that addresses the path traversal flaw
  • If a patch is unavailable, disable the HTTP server on the dash cam or block inbound traffic to the web port (e.g., TCP port 80/443) using network firewall rules
  • Ensure the dash cam is not connected to untrusted WiFi networks and that its removable storage is physically removed or encrypted when not in use

Generated by OpenCVE AI on September 25, 2026 at 03:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description The Botslab G980H dash camera firmware contains a path traversal vulnerability in its HTTP server. An attacker with access to the device's WiFi network could submit a crafted request to access files within the device's removable storage that were not intended to be directly accessible through the web server. Exposed files could include recordings, images, diagnostic logs, or firmware files.
Title Botslab G980H Dashcams Improper Limitation of a Pathname to a Restricted Directory
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-09-24T20:21:35.165Z

Reserved: 2026-09-10T15:25:29.837Z

Link: CVE-2026-82708

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-24T21:18:50.330

Modified: 2026-09-24T21:25:27.050

Link: CVE-2026-82708

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-25T03:15:14Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')