Session Management Vulnerability in Botslab G980H Dash Camera Firmware
CVE-2026-82566

8.7HIGH

Key Information:

Vendor

Botslab

Status
Vendor
CVE Published:
24 September 2026

What is CVE-2026-82566?

The Botslab G980H dash camera firmware has a session management flaw that allows an authentication state to persist after the associated client connection has been terminated. This means that under specific connection conditions, a new connection can mistakenly assume an existing session, remaining active until it is invalidated through a separate expiration mechanism. An unauthenticated attacker with adjacent network access could exploit this flaw, potentially gaining unauthorized access to the functions associated with another user's session. This poses significant security risks for users, making it critical to implement appropriate defensive measures.

Affected Version(s)

G980H 30010_QHG980HN5294SysFW+

G980H 58_QHG980HMCN5291SysFW+

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Julian of Software Secured reported this vulnerability to CISA.
.