CVE-2026-84399

8.8

Botslab · G980H

The Botslab G980H dash camera firmware features an authorization flaw where session identifiers are not correctly bound to the originating client, allowing unauthorized access to privileged commands.

Executive summary

A critical authorization vulnerability in the Botslab G980H dash camera firmware allows unauthenticated attackers with adjacent network access to hijack privileged sessions and execute unauthorized commands.

Vulnerability

This is an improper authorization vulnerability (CWE-863) occurring within the session based command functionality. The device fails to validate the authenticated context of a request, enabling an unauthenticated attacker to reuse valid session identifiers from other clients to perform sensitive operations.

Business impact

The vulnerability poses a severe risk to device integrity and user privacy. With a CVSS score of 8.8, this flaw could allow an attacker to gain full control over the camera functionality, leading to potential unauthorized surveillance or modification of device settings. The inability to ensure session integrity compromises the entire trust model of the device in a shared network environment.

Remediation

Immediate Action: Monitor official vendor advisories for the release of a firmware patch and apply it immediately upon availability.

Proactive Monitoring: Review network access logs for suspicious activity originating from unauthorized devices on the local network segment.

Compensating Controls: Restrict access to the dash camera management interface to trusted administrative devices only, and isolate the camera on a separate VLAN to limit the scope of potential adjacent network attacks.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the high CVSS score and the nature of the authorization flaw, this vulnerability represents a significant security risk. Administrators must prioritize the deployment of vendor-supplied firmware updates as soon as they are released. Until a patch is available, network segmentation remains the most effective strategy to prevent unauthorized access to the device management interface.

More Botslab CVEs

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources

Originally found and disclosed by Julian of Software Secured reported this vulnerability to CISA., per the CVE Program record.