Sensitive Data Exposure in Botslab G980H Dash Camera Firmware
CVE-2026-82716
5.1MEDIUM
What is CVE-2026-82716?
The Botslab G980H dash camera firmware suffers from a vulnerability where sensitive configuration data, including WiFi credentials, is stored insecurely in diagnostic logs generated during support operations. These logs can persist on removable storage, making them accessible to an unauthenticated attacker who has physical access to the media. As a result, there is a significant risk of unauthorized retrieval of sensitive information, posing a threat to user privacy and device security.
Affected Version(s)
G980H 30010_QHG980HN5294SysFW+
G980H 58_QHG980HMCN5291SysFW+
References
CVSS V4
Score:
5.1
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Physical
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Julian of Software Secured reported this vulnerability to CISA.
