---
id: CVE-2026-82708
title: >-
  The Botslab G980H dash camera firmware contains a path traversal vulnerability
  in its HTTP server
summary: >-
  The Botslab G980H dash camera firmware contains a path traversal vulnerability
  in its HTTP server. An attacker with access to the device's WiFi network could
  submit a crafted request to access files within the device's removable storage
  …
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-22
vendor: Botslab
product: G980H
affected:
  - G980H 30010_QHG980HN5294SysFW+
  - G980H 58_QHG980HMCN5291SysFW+
published: '2026-09-24'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T17:17:15.267'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-82708'
references:
  - url: >-
      https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-267-01.json
    label: ics-cert@hq.dhs.gov
  - url: 'https://www.botslab.com/pages/about-botslab'
    label: ics-cert@hq.dhs.gov
  - url: 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-267-01'
    label: ics-cert@hq.dhs.gov
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-25T16:21:06.946401Z'
ingestedAt: '2026-09-24T20:51:40.352Z'
---

## Overview

The Botslab G980H dash camera firmware contains a path traversal vulnerability in its HTTP server. An attacker with access to the device's WiFi network could submit a crafted request to access files within the device's removable storage that were not intended to be directly accessible through the web server. Exposed files could include recordings, images, diagnostic logs, or firmware files.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
