---
id: CVE-2026-79959
title: >-
  The Botslab G980H dash camera firmware contains a hard-coded root account
  password that cannot be changed by the user
summary: >-
  The Botslab G980H dash camera firmware contains a hard-coded root account
  password that cannot be changed by the user. An attacker who obtains the
  firmware or has physical access to the device could recover the credential and
  use it to o…
severity: medium
cvss: 6.8
cvssVector: 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-798
vendor: Botslab
product: G980H
affected:
  - G980H 30010_QHG980HN5294SysFW+
  - G980H 58_QHG980HMCN5291SysFW+
published: '2026-09-24'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T17:17:14.720'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-79959'
references:
  - url: >-
      https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-267-01.json
    label: ics-cert@hq.dhs.gov
  - url: 'https://www.botslab.com/pages/about-botslab'
    label: ics-cert@hq.dhs.gov
  - url: 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-267-01'
    label: ics-cert@hq.dhs.gov
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-25T16:19:50.495303Z'
ingestedAt: '2026-09-24T20:51:40.352Z'
epss: 0.00174
epssPercentile: 0.06054
---

## Overview

The Botslab G980H dash camera firmware contains a hard-coded root account password that cannot be changed by the user. An attacker who obtains the firmware or has physical access to the device could recover the credential and use it to obtain root access through the UART interface.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
