Authentication Flaw in Botslab G980H Dash Camera Firmware Exposing Root Access
CVE-2026-88956
7HIGH
What is CVE-2026-88956?
The Botslab G980H dash camera firmware presents a significant authentication vulnerability that can be exploited through the device's UART interface. This flaw allows unauthenticated individuals with physical access to gain root privileges without requiring a password for the privileged system interface. Additionally, this interface reveals the device's WiFi password during the device's startup process, providing further potential for unauthorized access and exploitation. Ensuring the security of the device is essential to prevent unauthorized access and safeguard sensitive information.
Affected Version(s)
G980H 30010_QHG980HN5294SysFW+
G980H 58_QHG980HMCN5291SysFW+
References
CVSS V4
Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Julian of Software Secured reported this vulnerability to CISA.
