{"id":"CVE-2026-84403","title":"The Botslab G980H dash camera firmware does not require authenticated pairing or client binding before permitting access to Bluetooth Low Energy communications and GATT characteristics","summary":"The Botslab G980H dash camera firmware does not require authenticated pairing or client binding before permitting access to Bluetooth Low Energy communications and GATT characteristics. An unauthenticated attacker within Bluetooth range …","severity":"medium","cvss":6.2,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-306"],"vendor":"Botslab","product":"G980H","affected":["G980H 30010_QHG980HN5294SysFW+","G980H 58_QHG980HMCN5291SysFW+"],"published":"2026-09-24","updated":"2026-09-24","sourceUpdated":"2026-09-24T21:25:27.050","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-84403","references":[{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-267-01.json","label":"ics-cert@hq.dhs.gov"},{"url":"https://www.botslab.com/pages/about-botslab","label":"ics-cert@hq.dhs.gov"},{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-267-01","label":"ics-cert@hq.dhs.gov"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-24T20:51:40.356Z","slug":"CVE-2026-84403","body":"## Overview\n\nThe Botslab G980H dash camera firmware does not require authenticated pairing or client binding before permitting access to Bluetooth Low Energy communications and GATT characteristics. An unauthenticated attacker within Bluetooth range could intercept or directly retrieve sensitive device information, including device identifiers, firmware information, and protected WiFi credentials.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":34,"depthScoreParts":{"impact":34.1,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}