Authorization Flaw in Botslab G980H Dash Camera Firmware
CVE-2026-84399
What is CVE-2026-84399?
The Botslab G980H dash camera firmware includes an authorization vulnerability within its session-based command functionality. This weakness arises from the insufficient association between authenticated sessions and their corresponding client connections. As a result, subsequent privileged actions rely solely on possession of a valid session identifier, lacking adequate validation of the requesting client's authenticated context. An unauthenticated attacker with adjacent network access may exploit this vulnerability, potentially leveraging valid session states linked to other clients to gain unauthorized access to sensitive functionalities.
Affected Version(s)
G980H 30010_QHG980HN5294SysFW+
G980H 58_QHG980HMCN5291SysFW+
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
