Botslab G980H Dashcams
CISA details multiple high-severity flaws in Botslab G980H dashcams that can bypass authentication over adjacent Wi-Fi.
CISA advisory ICSA-26-267-01 covers multiple vulnerabilities in Botslab G980H dashcam firmware builds 30010_QHG980HN5294SysFW+ and 58_QHG980HMCN5291SysFW+. Successful exploitation could let an adjacent-network attacker bypass authentication, read sensitive data, change configuration, and disrupt the device. Detailed issues include incorrect authorization, lingering sessions, predictable session identifiers, authentication replay, and a guessable default Wi-Fi password, with CVSS v3.1 scores up to 8.8. The transportation-sector product is deployed worldwide and the vendor is headquartered in China; the advisory does not report exploitation in the wild.