Impact
The Botslab G980H dash camera firmware has an authorization flaw where a session identifier is accepted for privileged operations without confirming that the connection actually authenticated that session. This weakness, identified as CWE‑863, allows an attacker who can reach the camera from a nearby network to hijack an existing authenticated session and execute commands reserved for privileged users, potentially exposing sensitive video data or manipulating camera behavior.
Affected Systems
The vulnerability impacts the Botslab G980H dash camera. No specific firmware version is listed, implying that all currently deployed units of this model may be affected. The vendor has not issued a patch or detailed workaround in the advisory.
Risk and Exploitability
The CVSS score of 8.7 classifies the flaw as high severity. EPSS is not available, but the advisory notes that the attack requires adjacent network access, indicating moderate exploitability. The flaw is not listed in the CISA KEV catalog, suggesting no publicly known exploitation. An attacker with local or nearby network access could exploit the session misassociation to perform privileged operations, threatening confidentiality and integrity of the camera’s data.
OpenCVE Enrichment