AI analysis
The Botslab G980H dash camera firmware contains a path traversal flaw (CWE-22) in its onboard HTTP server, which fails to properly constrain which files on the camera's removable storage can be requested. An attacker who can join the camera's WiFi network can send a crafted HTTP request containing path manipulation sequences to read files that were never intended to be served over the web interface, including dashcam recordings, photos, diagnostic logs, and firmware images. The issue scores 7.1 (high) under CVSS 4.0 because it requires no authentication or user interaction, though the adjacent-network attack vector means the attacker must first be within range of and connected to the camera's WiFi. Anyone using an affected G980H unit is impacted, with the practical risk being privacy exposure of in-car footage and device logs rather than control of the camera itself. There is no known public proof of concept, the flaw is not in CISA's KEV catalog, and no exploitation has been reported.
What to do: Apply the firmware update Botslab releases in response to the ICS advisory as soon as it is available, since no fixed version is named yet. In the meantime, change the camera's WiFi hotspot password from its default, keep WiFi disabled except when actively downloading footage, and avoid joining or configuring the camera on shared or public wireless networks. Consider whether the microSD card holds sensitive location-linked footage, and check the camera's logs and storage for signs of unexpected access.
Affected
| Botslab G980H Dash Camera | — |
Estimated exposure
nichelikely low tens of thousands of units (no public sales figures; single consumer dashcam model) — The G980H is one retail consumer dashcam model with no published install base, and the WiFi-only attack path means no devices are internet-exposed, so exposure is bounded by units sold rather than by internet scan data.
Description
The Botslab G980H dash camera firmware contains a path traversal vulnerability in its HTTP server. An attacker with access to the device's WiFi network could submit a crafted request to access files within the device's removable storage that were not intended to be directly accessible through the web server. Exposed files could include recordings, images, diagnostic logs, or firmware files.