AI analysis
The Botslab G980H dash camera firmware accepts a reusable authentication value without verifying its freshness or binding it to the client that originally authenticated (CWE-294). An attacker with adjacent network access, for example on the camera's Wi-Fi hotspot or a shared WLAN, can capture a valid authentication value from a legitimate app-to-camera session and replay it from a different client to open an authenticated session. This grants access to privileged device functionality, with high impact to confidentiality and integrity of the device and its footage. Owners of G980H units are at risk whenever the camera's wireless interface is in use, but exploitation requires network proximity rather than internet exposure. There is no evidence of exploitation in the wild, no public proof of concept, and the flaw is not listed in CISA's KEV catalog.
What to do: Monitor the ICS-CERT advisory and Botslab support channels for a fixed firmware release and upgrade the camera as soon as one is available. Until then, keep the camera's Wi-Fi hotspot disabled when not actively needed, change any default hotspot or app credentials, and avoid using the camera on shared or untrusted wireless networks where an authentication value could be captured.
Affected
| Botslab G980H dash camera (firmware) | — |
Estimated exposure
moderatePlausibly tens of thousands of devices in consumer use (rough order-of-magnitude estimate) — The G980H is a mid-tier consumer dashcam sold through online retail, and such models typically sell in the tens of thousands over their lifetime, but dashcams are not internet-scannable and no public sales or install figures exist, so this…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
The Botslab G980H dash camera firmware accepts a reusable authentication value without adequately verifying its freshness or association with the requesting client. An unauthenticated attacker with adjacent network access who captures a valid authentication value could replay it from another client to establish an authenticated session and access privileged device functionality.