Firmware Update Vulnerability in Botslab G980H Dash Camera
CVE-2026-81630

9.2CRITICAL

Key Information:

Vendor

Botslab

Status
Vendor
CVE Published:
24 September 2026

What is CVE-2026-81630?

The Botslab G980H dash camera is compromised by its firmware update mechanism, which fails to adequately verify the authenticity of firmware updates. Updates are downloaded over an unprotected connection and depend on an integrity value that can easily be spoofed, rather than a reliable cryptographic signature. This presents a significant risk, as an attacker positioned to intercept the firmware download, or someone with authentication privileges, could install malicious firmware and execute unauthorized commands on the device, ultimately jeopardizing the security for users.

Affected Version(s)

G980H 30010_QHG980HN5294SysFW+

G980H 58_QHG980HMCN5291SysFW+

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Julian of Software Secured reported this vulnerability to CISA.
.