Vulnerability in Botslab G980H Dash Camera Firmware
CVE-2026-85496

7.7HIGH

Key Information:

Vendor

Botslab

Status
Vendor
CVE Published:
24 September 2026

What is CVE-2026-85496?

The firmware of the Botslab G980H dash camera exhibits a significant security flaw related to the generation of session identifiers. Instead of using a robust, unpredictable source, the firmware relies on a limited sequential value space, which can be easily exploited. An unauthenticated attacker with adjacent network access could potentially observe an active session and deduce a valid session identifier, thereby bypassing the intended authorization measures and gaining unauthorized access to sensitive functions. This vulnerability underscores the importance of implementing strong randomness in session management to safeguard against session hijacking and unauthorized access.

Affected Version(s)

G980H 30010_QHG980HN5294SysFW+

G980H 58_QHG980HMCN5291SysFW+

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Julian of Software Secured reported this vulnerability to CISA.
.