---
id: CVE-2026-84403
title: >-
  The Botslab G980H dash camera firmware does not require authenticated pairing
  or client binding before permitting access to Bluetooth Low Energy
  communications and GATT characteristics
summary: >-
  The Botslab G980H dash camera firmware does not require authenticated pairing
  or client binding before permitting access to Bluetooth Low Energy
  communications and GATT characteristics. An unauthenticated attacker within
  Bluetooth range …
severity: medium
cvss: 6.2
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-306
vendor: Botslab
product: G980H
affected:
  - G980H 30010_QHG980HN5294SysFW+
  - G980H 58_QHG980HMCN5291SysFW+
published: '2026-09-24'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T17:17:15.643'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-84403'
references:
  - url: >-
      https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-267-01.json
    label: ics-cert@hq.dhs.gov
  - url: 'https://www.botslab.com/pages/about-botslab'
    label: ics-cert@hq.dhs.gov
  - url: 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-267-01'
    label: ics-cert@hq.dhs.gov
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-25T16:24:46.709740Z'
ingestedAt: '2026-09-24T20:51:40.356Z'
epss: 0.00122
epssPercentile: 0.01729
---

## Overview

The Botslab G980H dash camera firmware does not require authenticated pairing or client binding before permitting access to Bluetooth Low Energy communications and GATT characteristics. An unauthenticated attacker within Bluetooth range could intercept or directly retrieve sensitive device information, including device identifiers, firmware information, and protected WiFi credentials.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
