CVE-2026-82566
8.8Botslab · G980H
The Botslab G980H dash camera firmware fails to properly expire sessions after a client connection is terminated, potentially allowing unauthorized access to existing sessions.
Executive summary
The Botslab G980H dash camera contains a session management flaw that allows an unauthenticated, adjacent attacker to hijack existing user sessions.
Vulnerability
This vulnerability, categorized as CWE-613, occurs because the firmware does not invalidate session states when a client disconnects. An unauthenticated attacker located on the adjacent network can exploit this to inherit a previous user session, gaining full access to camera functions.
Business impact
This vulnerability carries a CVSS score of 8.8, reflecting its high severity due to the potential for total unauthorized access to the device. Successful exploitation allows an attacker to manipulate camera settings or access sensitive data, resulting in significant privacy compromises and potential loss of device integrity.
Remediation
Immediate Action: Consult the official Botslab security advisory for firmware update availability and apply all recommended patches immediately.
Proactive Monitoring: Monitor network access logs for unusual connection patterns or multiple concurrent sessions originating from the same device identifier.
Compensating Controls: Restrict access to the camera's management interface to trusted network segments and utilize network isolation to prevent unauthorized adjacent access.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the high severity of this session management flaw and the potential for unauthorized administrative access, users must prioritize the application of vendor-provided firmware updates. Until a patch is confirmed and applied, organizations should implement strict network segmentation to minimize the risk of adjacent access by malicious actors.
More Botslab CVEs
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section
Sources
Originally found and disclosed by Julian of Software Secured reported this vulnerability to CISA., per the CVE Program record.