CVE-2026-81630High· 8.1▾ TwilightThe Botslab G980H dash camera firmware does not adequately verify the authenticity of firmware updates. The update process retrieves firmware through an unprotected connection and relies on an integrity value supplied with the firmware i…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 44.6 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
The Botslab G980H dash camera firmware does not adequately verify the authenticity of firmware updates. The update process retrieves firmware through an unprotected connection and relies on an integrity value supplied with the firmware instead of a trusted cryptographic signature. A suitably positioned attacker who intercepts a firmware download, or an authenticated attacker who submits a crafted update, could install modified firmware and execute unauthorized code on the device.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-84403Medium· 6.2The Botslab G980H dash camera firmware does not require authenticated pairing or client binding before permitting access to Bluetooth Low Energy communications and GATT characteristics
CVE-2026-82716Medium· 4.6The Botslab G980H dash camera firmware includes sensitive configuration information, including WiFi credentials, in diagnostic logs generated during the support process
CVE-2026-75558Medium· 5.3The Botslab G980H dash camera firmware uses a hard-coded cryptographic key and initialization vector to protect WiFi credentials communicated by the device
CVE-2026-87118Medium· 5.7The Botslab G980H dash camera firmware contains an out of bounds write vulnerability in its command processing functionality
CVE-2026-79959Medium· 6.8The Botslab G980H dash camera firmware contains a hard-coded root account password that cannot be changed by the user
CVE-2026-82708Medium· 6.5The Botslab G980H dash camera firmware contains a path traversal vulnerability in its HTTP server