CVE-2026-85496
8.8Botslab · G980H
The Botslab G980H dash camera firmware utilizes predictable, sequential session identifiers, allowing unauthenticated attackers on the adjacent network to bypass authorization controls.
Executive summary
A critical session management flaw in the Botslab G980H dash camera allows unauthenticated attackers to hijack active sessions and gain unauthorized access.
Vulnerability
The device uses a weak, predictable sequential value space for generating session identifiers, which fails to provide sufficient entropy. An unauthenticated attacker with adjacent network access can predict these tokens to bypass authentication and intercept or control the camera session.
Business impact
Successful exploitation allows an unauthorized party to bypass authentication, potentially leading to unauthorized access to the camera feed or device settings. Given the CVSS score of 8.8, this vulnerability presents a high risk of sensitive data compromise and loss of operational integrity for users relying on the device for monitoring.
Remediation
Immediate Action: Contact the vendor immediately to obtain the latest firmware update, as no public patch version is currently identified.
Proactive Monitoring: Monitor network traffic for anomalous connection attempts or repeated session authentication requests originating from unknown or unauthorized devices on the adjacent network.
Compensating Controls: Restrict access to the camera by placing it on an isolated network segment and ensuring that only authorized devices can communicate with the camera over the local network.
Exploitation status
Public Exploit Available: No
Analyst recommendation
This vulnerability is severe due to the ease of session hijacking and the lack of required authentication for the attack. Organizations utilizing the Botslab G980H should treat this as a high priority item and verify firmware status with the vendor immediately to mitigate the risk of unauthorized access.
More Botslab CVEs
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section
Sources
Originally found and disclosed by Julian of Software Secured reported this vulnerability to CISA., per the CVE Program record.