Description
The Botslab G980H dash camera firmware generates session identifiers using a small sequential value space rather than a suitably unpredictable source. An unauthenticated attacker with adjacent network access and knowledge that an active session exists could potentially determine a valid session identifier and use it to bypass intended authorization controls.
Published: 2026-09-24
Score: 7.7 High
EPSS: n/a
KEV: No
Impact: Session Identifier Predictability Leading to Authorization Bypass
Action: Prompt Patch
AI Analysis

Impact

The firmware of Botslab G980H dash cameras generates session identifiers from a small, sequential value space instead of a cryptographically secure random source. This flaw allows an unauthenticated attacker who has access to the local network and knows that a device session is active to guess or compute a valid session identifier. By acquiring a legitimate identifier, the attacker can obtain unauthorized access to the dash camera’s privileged functions, potentially exposing recorded video, disabling recording, or altering device settings. The weakness corresponds to predictable random number generation.

Affected Systems

Botslab G980H dash cameras are affected. No specific firmware revision or version range is listed; all users running the current firmware should be treated as at risk until an update is issued. Products outside the G980H model are not impacted.

Risk and Exploitability

The CVSS score of 7.7 indicates high severity. With EPSS not available, the precise exploitation probability is unknown, but the presence of adjacent network access simplifies the attack. The vulnerability is not listed in CISA’s KEV catalog, implying no publicly documented exploits yet. However, the attack would require only network reachability and knowledge of an active session, conditions often satisfied within a private network or by attackers who have compromised a neighbor device. The most likely attack vector is local network exploitation, where the attacker can sniff or inject traffic to observe or manipulate session identifiers.

Generated by OpenCVE AI on September 25, 2026 at 03:14 UTC.

Remediation

Vendor Workaround

Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information: https://www.botslab.com/pages/about-botslab


OpenCVE Recommended Actions

  • Contact Botslab to request a firmware update that implements a secure random number generator for session identifiers
  • Block or isolate the dash camera on a separate VLAN or subnet to limit local network access to the device
  • Enable network monitoring to detect anomalous or out-of-range session identifiers being used by clients

Generated by OpenCVE AI on September 25, 2026 at 03:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Description The Botslab G980H dash camera firmware generates session identifiers using a small sequential value space rather than a suitably unpredictable source. An unauthenticated attacker with adjacent network access and knowledge that an active session exists could potentially determine a valid session identifier and use it to bypass intended authorization controls.
Title Botslab G980H Dashcams Generation of Predictable Numbers or Identifiers
Weaknesses CWE-340
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 7.7, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-09-24T19:47:33.970Z

Reserved: 2026-09-10T15:31:03.069Z

Link: CVE-2026-85496

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-24T20:17:32.890

Modified: 2026-09-24T21:25:27.050

Link: CVE-2026-85496

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-25T03:15:14Z

Weaknesses
  • CWE-340

    Generation of Predictable Numbers or Identifiers