AllCyberNews

CVE-2026-82566

Botslab G980H Dashcams Insufficient session expiration

CVSS 8.7 high · Botslab G980H · published 2026-09-24

The Botslab G980H dash camera firmware contains a session management vulnerability in which authentication state can remain valid after the associated client connection has been terminated or replaced. Under certain connection conditions, a newly established connection can displace an existing client while previously established session state remains active until a separate expiration mechanism invalidates it. An unauthenticated attacker with adjacent network access could potentially take advantage of this residual authentication state to access functionality associated with another client's session.

Coverage 1 source

  1. 2026-09-24 CISA Cybersecurity Advisories high Botslab G980H Dashcams

    Multiple vulnerabilities in Botslab G980H Dashcams could allow attackers to bypass authentication and gain unauthorized access.

Mentioned with

CVE-2026-75558 CVE-2026-77967 CVE-2026-82716 CVE-2026-84399 CVE-2026-84403 CVE-2026-85496 CVE-2026-88761

Also covered