Authentication Bypass Vulnerability in Botslab G980H Dash Camera Firmware
CVE-2026-77967

8.6HIGH

Key Information:

Vendor

Botslab

Status
Vendor
CVE Published:
24 September 2026

What is CVE-2026-77967?

The Botslab G980H dash camera firmware contains a security flaw that allows an unauthenticated attacker with adjacent network access to exploit the system. This vulnerability arises from the firmware's failure to adequately verify the freshness or client association of a reusable authentication value. As a result, an attacker could capture a valid authentication token from one client and replay it to impersonate that client, granting unauthorized access to sensitive device functionalities. This could potentially lead to unauthorized control over the dash camera, compromising user privacy and security.

Affected Version(s)

G980H 30010_QHG980HN5294SysFW+

G980H 58_QHG980HMCN5291SysFW+

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Julian of Software Secured reported this vulnerability to CISA.
.