Authorization Flaw in Botslab G980H Dash Camera Firmware
CVE-2026-84399

8.7HIGH

Key Information:

Vendor

Botslab

Status
Vendor
CVE Published:
24 September 2026

What is CVE-2026-84399?

The Botslab G980H dash camera firmware includes an authorization vulnerability within its session-based command functionality. This weakness arises from the insufficient association between authenticated sessions and their corresponding client connections. As a result, subsequent privileged actions rely solely on possession of a valid session identifier, lacking adequate validation of the requesting client's authenticated context. An unauthenticated attacker with adjacent network access may exploit this vulnerability, potentially leveraging valid session states linked to other clients to gain unauthorized access to sensitive functionalities.

Affected Version(s)

G980H 30010_QHG980HN5294SysFW+

G980H 58_QHG980HMCN5291SysFW+

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Julian of Software Secured reported this vulnerability to CISA.
.