Authentication Bypass Vulnerability in Botslab G980H Dash Camera Firmware
CVE-2026-77967
8.6HIGH
What is CVE-2026-77967?
The Botslab G980H dash camera firmware contains a security flaw that allows an unauthenticated attacker with adjacent network access to exploit the system. This vulnerability arises from the firmware's failure to adequately verify the freshness or client association of a reusable authentication value. As a result, an attacker could capture a valid authentication token from one client and replay it to impersonate that client, granting unauthorized access to sensitive device functionalities. This could potentially lead to unauthorized control over the dash camera, compromising user privacy and security.
Affected Version(s)
G980H 30010_QHG980HN5294SysFW+
G980H 58_QHG980HMCN5291SysFW+
References
CVSS V4
Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Julian of Software Secured reported this vulnerability to CISA.
