Impact
The firmware of Botslab G980H dash cameras generates session identifiers from a small, sequential value space instead of a cryptographically secure random source. This flaw allows an unauthenticated attacker who has access to the local network and knows that a device session is active to guess or compute a valid session identifier. By acquiring a legitimate identifier, the attacker can obtain unauthorized access to the dash camera’s privileged functions, potentially exposing recorded video, disabling recording, or altering device settings. The weakness corresponds to predictable random number generation.
Affected Systems
Botslab G980H dash cameras are affected. No specific firmware revision or version range is listed; all users running the current firmware should be treated as at risk until an update is issued. Products outside the G980H model are not impacted.
Risk and Exploitability
The CVSS score of 7.7 indicates high severity. With EPSS not available, the precise exploitation probability is unknown, but the presence of adjacent network access simplifies the attack. The vulnerability is not listed in CISA’s KEV catalog, implying no publicly documented exploits yet. However, the attack would require only network reachability and knowledge of an active session, conditions often satisfied within a private network or by attackers who have compromised a neighbor device. The most likely attack vector is local network exploitation, where the attacker can sniff or inject traffic to observe or manipulate session identifiers.
OpenCVE Enrichment