---
id: CVE-2026-81630
title: >-
  The Botslab G980H dash camera firmware does not adequately verify the
  authenticity of firmware updates
summary: >-
  The Botslab G980H dash camera firmware does not adequately verify the
  authenticity of firmware updates. The update process retrieves firmware
  through an unprotected connection and relies on an integrity value supplied
  with the firmware i…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-345
vendor: Botslab
product: G980H
affected:
  - G980H 30010_QHG980HN5294SysFW+
  - G980H 58_QHG980HMCN5291SysFW+
published: '2026-09-24'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T17:17:15.007'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-81630'
references:
  - url: >-
      https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-267-01.json
    label: ics-cert@hq.dhs.gov
  - url: 'https://www.botslab.com/pages/about-botslab'
    label: ics-cert@hq.dhs.gov
  - url: 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-267-01'
    label: ics-cert@hq.dhs.gov
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-25T16:22:58.800724Z'
ingestedAt: '2026-09-24T20:51:40.354Z'
epss: 0.00194
epssPercentile: 0.08033
---

## Overview

The Botslab G980H dash camera firmware does not adequately verify the authenticity of firmware updates. The update process retrieves firmware through an unprotected connection and relies on an integrity value supplied with the firmware instead of a trusted cryptographic signature. A suitably positioned attacker who intercepts a firmware download, or an authenticated attacker who submits a crafted update, could install modified firmware and execute unauthorized code on the device.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
