Description
The Botslab G980H dash camera firmware contains an authentication vulnerability in the root account exposed through the device's UART interface. The affected account does not require a password before granting access to a privileged system interface, and the interface also displays the device's WiFi password during startup. An unauthenticated attacker with physical access to the device could connect to the UART interface, obtain root privileges, and recover the WiFi password.
Published: 2026-09-24
Score: 7 High
EPSS: n/a
KEV: No
Impact: Privilege Escalation via authentication bypass on UART
Action: Contact Vendor
AI Analysis

Impact

The Botslab G980H dash camera firmware contains an authentication flaw that allows an attacker with physical access to connect to the UART interface and obtain root privileges without providing a password. The same interface displays the device’s WiFi password during startup, giving the attacker lower‑level network access as well. This lack of authentication is a clear enforcement issue (CWE‑306) that enables full control over the device, including firmware tampering, data exfiltration, and unauthorized command execution.

Affected Systems

Botslab G980H dash cameras. Firmware versions are unspecified; the vulnerability applies to all units that expose a root account through the UART port, regardless of firmware revision. No specific version details are provided by the CNA.

Risk and Exploitability

The assigned CVSS score of 7 indicates high severity. EPSS data is not available, so the exploitation probability cannot be quantified precisely, but the presence of an unprotected UART port means that a local attacker can readily craft the exploit. The issue is not listed in CISA’s KEV catalog, and no publicly known exploit has been reported. The most likely attack vector is a physical attacker who can attach to the UART interface during maintenance or supply chain handling.

Generated by OpenCVE AI on September 25, 2026 at 03:48 UTC.

Remediation

Vendor Workaround

Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information: https://www.botslab.com/pages/about-botslab


OpenCVE Recommended Actions

  • Contact Botslab to obtain a firmware patch or detailed mitigation guidance.
  • Disable or physically block the UART interface and enforce strict physical security controls to prevent unauthorized access.
  • After restricting UART, change the WiFi password, monitor wireless activity for anomalies, and consider network segmentation to isolate the dash camera from critical assets.

Generated by OpenCVE AI on September 25, 2026 at 03:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description The Botslab G980H dash camera firmware contains an authentication vulnerability in the root account exposed through the device's UART interface. The affected account does not require a password before granting access to a privileged system interface, and the interface also displays the device's WiFi password during startup. An unauthenticated attacker with physical access to the device could connect to the UART interface, obtain root privileges, and recover the WiFi password.
Title Botslab G980H Dashcams Missing Authentication for Critical Function
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 7, 'vector': 'CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-09-24T19:59:50.348Z

Reserved: 2026-09-10T15:31:03.083Z

Link: CVE-2026-88956

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-24T20:17:33.793

Modified: 2026-09-24T21:25:27.050

Link: CVE-2026-88956

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-25T04:00:15Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function