AI analysis
The Botslab G980H dash camera firmware fails to invalidate authentication state when a client connection is terminated or displaced: a newly connecting client can take over the link while the previous client's session credentials remain active until a separate expiration timer eventually clears them. An unauthenticated attacker with adjacent network access — realistically the camera's own Wi-Fi hotspot, which dashcams broadcast for phone-app pairing — can exploit this residual state to piggyback on another user's session and access camera functionality. The CNA (CISA ICS-CERT) scores this CVSS v4.0 8.7 with high impact on confidentiality, integrity, and availability, meaning an attacker could plausibly view or download recorded footage (including in-cabin audio/video), alter settings, or disrupt the device. Affected parties are consumers running the G980H in their vehicles; the advisory does not list specific firmware versions. No public proof-of-concept exists, there is no known exploitation in the wild, and the CVE is not on CISA's KEV list.
What to do: Check the Botslab app and vendor support pages for a firmware update and install it as soon as a fixed release is published, since the advisory does not identify patched versions. Because the attack requires adjacent network access, replace the camera's default Wi-Fi hotspot password with a strong, unique one and disable its Wi-Fi when you are not reviewing footage or downloading clips. Treat saved recordings and any in-cabin audio as potentially accessible to someone within Wi-Fi range of a powered-on camera until the firmware is updated.
Affected
| Botslab G980H Dash Camera | — |
Estimated exposure
moderate≈10,000–100,000 consumer units worldwide (rough order-of-magnitude guess) — This is a single consumer dashcam model from a niche brand, and units are mobile in-vehicle devices invisible to internet-wide scans, so the estimate rests on typical sales volumes for this product class rather than any measured count.
Description
The Botslab G980H dash camera firmware contains a session management vulnerability in which authentication state can remain valid after the associated client connection has been terminated or replaced. Under certain connection conditions, a newly established connection can displace an existing client while previously established session state remains active until a separate expiration mechanism invalidates it. An unauthenticated attacker with adjacent network access could potentially take advantage of this residual authentication state to access functionality associated with another client's session.