Botslab has 14 CVEs on record. Disclosure cadence is accelerating: 14 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 14. The median CVSS is 6.7 (medium). None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.7
- Publish → KEV
- —
- Last 90 days
- 14 prev 0
Weakness classes
Products
- G980H 14
Worst active — by depth score
CVE-2026-85496High· 8.8The Botslab G980H dash camera firmware generates session identifiers using a small sequential value space rather than a suitably unpredictable source48CVE-2026-84399High· 8.8The Botslab G980H dash camera firmware contains an authorization vulnerability in its session based command functionality48CVE-2026-82566High· 8.8The Botslab G980H dash camera firmware contains a session management vulnerability in which authentication state can remain valid after the associated client connection has been terminated or replaced48CVE-2026-81630High· 8.1The Botslab G980H dash camera firmware does not adequately verify the authenticity of firmware updates45CVE-2026-77967High· 8.1The Botslab G980H dash camera firmware accepts a reusable authentication value without adequately verifying its freshness or association with the requesting client45
Botslab vulnerabilities
CVEs affecting Botslab, newest first. Open any entry for full detail, references, and exploit status.
14 CVEsRSS
CVE-2026-84403Medium· 6.2The Botslab G980H dash camera firmware does not require authenticated pairing or client binding before permitting access to Bluetooth Low Energy communications and GATT characteristics
The Botslab G980H dash camera firmware does not require authenticated pairing or client binding before permitting access to Bluetooth Low Energy communications and GATT characteristics. An unauthenticated attacker within Bluetooth range …
CVE-2026-82716Medium· 4.6The Botslab G980H dash camera firmware includes sensitive configuration information, including WiFi credentials, in diagnostic logs generated during the support process
The Botslab G980H dash camera firmware includes sensitive configuration information, including WiFi credentials, in diagnostic logs generated during the support process. These logs remain accessible on removable storage after the support…
CVE-2026-81630High· 8.1The Botslab G980H dash camera firmware does not adequately verify the authenticity of firmware updates
The Botslab G980H dash camera firmware does not adequately verify the authenticity of firmware updates. The update process retrieves firmware through an unprotected connection and relies on an integrity value supplied with the firmware i…
CVE-2026-75558Medium· 5.3The Botslab G980H dash camera firmware uses a hard-coded cryptographic key and initialization vector to protect WiFi credentials communicated by the device
The Botslab G980H dash camera firmware uses a hard-coded cryptographic key and initialization vector to protect WiFi credentials communicated by the device. An attacker who obtains the protected credential and extracts the cryptographic …
CVE-2026-87118Medium· 5.7The Botslab G980H dash camera firmware contains an out of bounds write vulnerability in its command processing functionality
The Botslab G980H dash camera firmware contains an out of bounds write vulnerability in its command processing functionality. An authenticated attacker with adjacent network access could submit crafted command data that corrupts memory, …
CVE-2026-82708Medium· 6.5The Botslab G980H dash camera firmware contains a path traversal vulnerability in its HTTP server
The Botslab G980H dash camera firmware contains a path traversal vulnerability in its HTTP server. An attacker with access to the device's WiFi network could submit a crafted request to access files within the device's removable storage …
CVE-2026-79959Medium· 6.8The Botslab G980H dash camera firmware contains a hard-coded root account password that cannot be changed by the user
The Botslab G980H dash camera firmware contains a hard-coded root account password that cannot be changed by the user. An attacker who obtains the firmware or has physical access to the device could recover the credential and use it to o…
CVE-2026-82585Medium· 6.5The Botslab G980H dash camera firmware transmits sensitive information over unencrypted HTTP and RTSP connections
The Botslab G980H dash camera firmware transmits sensitive information over unencrypted HTTP and RTSP connections. An attacker capable of intercepting communications on the device's WiFi network could obtain stored recordings, live video…
CVE-2026-88956Medium· 6.8The Botslab G980H dash camera firmware contains an authentication vulnerability in the root account exposed through the device's UART interface
The Botslab G980H dash camera firmware contains an authentication vulnerability in the root account exposed through the device's UART interface. The affected account does not require a password before granting access to a privileged syst…
CVE-2026-88761Medium· 5.3The Botslab G980H dash camera firmware generates the default WiFi password using predictable device information, portions of which are advertised by the product
The Botslab G980H dash camera firmware generates the default WiFi password using predictable device information, portions of which are advertised by the product. An unauthenticated attacker within WiFi range could potentially determine t…
CVE-2026-85496High· 8.8The Botslab G980H dash camera firmware generates session identifiers using a small sequential value space rather than a suitably unpredictable source
The Botslab G980H dash camera firmware generates session identifiers using a small sequential value space rather than a suitably unpredictable source. An unauthenticated attacker with adjacent network access and knowledge that an active …
CVE-2026-77967High· 8.1The Botslab G980H dash camera firmware accepts a reusable authentication value without adequately verifying its freshness or association with the requesting client
The Botslab G980H dash camera firmware accepts a reusable authentication value without adequately verifying its freshness or association with the requesting client. An unauthenticated attacker with adjacent network access who captures a …
CVE-2026-84399High· 8.8The Botslab G980H dash camera firmware contains an authorization vulnerability in its session based command functionality
The Botslab G980H dash camera firmware contains an authorization vulnerability in its session based command functionality. The product does not sufficiently associate an authenticated session with the client connection that established i…
CVE-2026-82566High· 8.8The Botslab G980H dash camera firmware contains a session management vulnerability in which authentication state can remain valid after the associated client connection has been terminated or replaced
The Botslab G980H dash camera firmware contains a session management vulnerability in which authentication state can remain valid after the associated client connection has been terminated or replaced. Under certain connection conditions…