Vulnerability in Botslab G980H Dash Camera Firmware
CVE-2026-85496
What is CVE-2026-85496?
The firmware of the Botslab G980H dash camera exhibits a significant security flaw related to the generation of session identifiers. Instead of using a robust, unpredictable source, the firmware relies on a limited sequential value space, which can be easily exploited. An unauthenticated attacker with adjacent network access could potentially observe an active session and deduce a valid session identifier, thereby bypassing the intended authorization measures and gaining unauthorized access to sensitive functions. This vulnerability underscores the importance of implementing strong randomness in session management to safeguard against session hijacking and unauthorized access.
Affected Version(s)
G980H 30010_QHG980HN5294SysFW+
G980H 58_QHG980HMCN5291SysFW+
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
