Session-Binding Flaw in Botslab G980H Dashcam Lets Adjacent Attackers Hijack Privileges
AI analysis
The Botslab G980H dash camera firmware does not tie an authenticated session to the client connection that established it, so privileged commands are authorized based only on possession of a valid session identifier (CWE-863, incorrect authorization). An unauthenticated attacker with adjacent network access - for example within range of the camera's Wi-Fi hotspot or on the same local network - can reuse valid session state belonging to another client, such as the owner's paired phone, to invoke privileged functionality. The flaw carries a CVSS 4.0 score of 8.7 with high impact to confidentiality, integrity, and availability of the device, effectively granting full privileged control of the camera. Only owners of the G980H model are affected, and exploitation requires network proximity rather than internet exposure, since the attack vector is adjacent-network. There is no known public proof of concept, the CVE is not on the CISA KEV list, and no exploitation has been observed.
What to do: Check the Botslab vendor site and companion app for a firmware update, as the advisory lists no fixed version. Until patched, disable the camera's Wi-Fi hotspot and Bluetooth when not actively in use and set a strong, unique hotspot password, since exploitation requires an attacker on the same adjacent network. Avoid pairing or operating the camera in high-density settings where a nearby attacker could share the network and replay a valid session.
Affected
| Botslab G980H dash camera firmware | — |
Estimated exposure
unknown (single consumer dashcam model; no sales, install, or internet-scan figures available) — No public sales data, market-share figures, or internet-exposure scan counts exist for this device, and dash cams are typically paired to a phone over local Wi-Fi/Bluetooth rather than exposed to the internet, so scan-based counts cannot…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
The Botslab G980H dash camera firmware contains an authorization vulnerability in its session based command functionality. The product does not sufficiently associate an authenticated session with the client connection that established it, and subsequent privileged operations rely on possession of a valid session identifier without adequately validating the requesting client's authenticated context. An unauthenticated attacker with adjacent network access could potentially use valid session state associated with another client to access privileged functionality.