---
id: CVE-2026-88956
title: >-
  The Botslab G980H dash camera firmware contains an authentication
  vulnerability in the root account exposed through the device's UART interface
summary: >-
  The Botslab G980H dash camera firmware contains an authentication
  vulnerability in the root account exposed through the device's UART interface.
  The affected account does not require a password before granting access to a
  privileged syst…
severity: medium
cvss: 6.8
cvssVector: 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-306
vendor: Botslab
product: G980H
affected:
  - G980H 30010_QHG980HN5294SysFW+
  - G980H 58_QHG980HMCN5291SysFW+
published: '2026-09-24'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T17:17:18.660'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-88956'
references:
  - url: >-
      https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-267-01.json
    label: ics-cert@hq.dhs.gov
  - url: 'https://www.botslab.com/pages/about-botslab'
    label: ics-cert@hq.dhs.gov
  - url: 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-267-01'
    label: ics-cert@hq.dhs.gov
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-25T16:33:35.486957Z'
ingestedAt: '2026-09-24T20:51:40.260Z'
epss: 0.00218
epssPercentile: 0.1089
---

## Overview

The Botslab G980H dash camera firmware contains an authentication vulnerability in the root account exposed through the device's UART interface. The affected account does not require a password before granting access to a privileged system interface, and the interface also displays the device's WiFi password during startup. An unauthenticated attacker with physical access to the device could connect to the UART interface, obtain root privileges, and recover the WiFi password.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
