Description
The Botslab G980H dash camera firmware contains an authorization vulnerability in its session based command functionality. The product does not sufficiently associate an authenticated session with the client connection that established it, and subsequent privileged operations rely on possession of a valid session identifier without adequately validating the requesting client's authenticated context. An unauthenticated attacker with adjacent network access could potentially use valid session state associated with another client to access privileged functionality.
Published: 2026-09-24
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Authorization Bypass via Session Misassociation
Action: Contact Vendor
AI Analysis

Impact

The Botslab G980H dash camera firmware has an authorization flaw where a session identifier is accepted for privileged operations without confirming that the connection actually authenticated that session. This weakness, identified as CWE‑863, allows an attacker who can reach the camera from a nearby network to hijack an existing authenticated session and execute commands reserved for privileged users, potentially exposing sensitive video data or manipulating camera behavior.

Affected Systems

The vulnerability impacts the Botslab G980H dash camera. No specific firmware version is listed, implying that all currently deployed units of this model may be affected. The vendor has not issued a patch or detailed workaround in the advisory.

Risk and Exploitability

The CVSS score of 8.7 classifies the flaw as high severity. EPSS is not available, but the advisory notes that the attack requires adjacent network access, indicating moderate exploitability. The flaw is not listed in the CISA KEV catalog, suggesting no publicly known exploitation. An attacker with local or nearby network access could exploit the session misassociation to perform privileged operations, threatening confidentiality and integrity of the camera’s data.

Generated by OpenCVE AI on September 25, 2026 at 03:52 UTC.

Remediation

Vendor Workaround

Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information: https://www.botslab.com/pages/about-botslab


OpenCVE Recommended Actions

  • Contact Botslab immediately and request a firmware update that addresses the session authorization flaw.
  • Segment the G980H camera on a dedicated VLAN and block the command ports from non‑trusted devices to prevent adjacent network access.
  • Enable and regularly review audit logs for unexpected privileged command usage to detect potential misuse.

Generated by OpenCVE AI on September 25, 2026 at 03:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 25 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Botslab
Botslab g980h
Vendors & Products Botslab
Botslab g980h

Thu, 24 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 24 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Description The Botslab G980H dash camera firmware contains an authorization vulnerability in its session based command functionality. The product does not sufficiently associate an authenticated session with the client connection that established it, and subsequent privileged operations rely on possession of a valid session identifier without adequately validating the requesting client's authenticated context. An unauthenticated attacker with adjacent network access could potentially use valid session state associated with another client to access privileged functionality.
Title Botslab G980H Dashcams Incorrect Authorization
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-09-24T19:35:47.169Z

Reserved: 2026-09-10T15:31:03.061Z

Link: CVE-2026-84399

cve-icon Vulnrichment

Updated: 2026-09-24T19:35:44.151Z

cve-icon NVD

Status : Deferred

Published: 2026-09-24T20:17:32.673

Modified: 2026-09-24T21:25:27.050

Link: CVE-2026-84399

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-25T14:15:46Z

Weaknesses