Description
The Botslab G980H dash camera firmware includes sensitive configuration information, including WiFi credentials, in diagnostic logs generated during the support process. These logs remain accessible on removable storage after the support operation has completed. An unauthenticated attacker with physical access to the storage media could retrieve the logs and obtain sensitive device information.
Published: 2026-09-24
Score: 5.1 Medium
EPSS: n/a
KEV: No
Impact: Exfiltration of sensitive device credentials
Action: Vendor Consultation
AI Analysis

Impact

The Botslab G980H dash camera firmware records sensitive configuration information such as WiFi credentials in diagnostic logs generated during a support operation. After the operation, these logs remain available on removable storage media and contain data that an unauthorized party could read. An attacker who gains physical access to the storage can retrieve the logs and obtain confidential device information, compromising the confidentiality of the system configuration.

Affected Systems

The vulnerability affects Botslab G980H dash cameras. No specific firmware version numbers are listed, indicating that all firmware releases from this product line are potentially impacted.

Risk and Exploitability

The CVSS score of 5.1 indicates moderate severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is physical; the attacker must possess the removable media used during the support process. No network or privileged access is required, but physical access is necessary, suggesting that the exploitation likelihood is contingent on an attacker’s proximity to the device. The data exposed are credentials and configuration details, so the impact is primarily on confidentiality.

Generated by OpenCVE AI on September 25, 2026 at 04:22 UTC.

Remediation

Vendor Workaround

Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information: https://www.botslab.com/pages/about-botslab


OpenCVE Recommended Actions

  • Contact Botslab for guidance via https://www.botslab.com/pages/about-botslab
  • Securely erase or dispose of any removable storage used for logs after each support operation and limit physical access to the device.
  • Manually review content of log files on removable storage after each support operation and delete any sensitive configuration data.

Generated by OpenCVE AI on September 25, 2026 at 04:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description The Botslab G980H dash camera firmware includes sensitive configuration information, including WiFi credentials, in diagnostic logs generated during the support process. These logs remain accessible on removable storage after the support operation has completed. An unauthenticated attacker with physical access to the storage media could retrieve the logs and obtain sensitive device information.
Title Botslab G980H Dashcams Insertion of Sensitive Information into Log File
Weaknesses CWE-532
References
Metrics cvssV3_1

{'score': 4.6, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-09-24T20:02:57.856Z

Reserved: 2026-09-10T15:31:03.086Z

Link: CVE-2026-82716

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-24T21:18:50.483

Modified: 2026-09-24T21:25:27.050

Link: CVE-2026-82716

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-25T04:30:08Z

Weaknesses
  • CWE-532

    Insertion of Sensitive Information into Log File