CVE-2026-84399
Botslab G980H Dashcams Incorrect Authorization
The Botslab G980H dash camera firmware contains an authorization vulnerability in its session based command functionality. The product does not sufficiently associate an authenticated session with the client connection that established it, and subsequent privileged operations rely on possession of a valid session identifier without adequately validating the requesting client's authenticated context. An unauthenticated attacker with adjacent network access could potentially use valid session state associated with another client to access privileged functionality.
Coverage 1 source
-
2026-09-24
CISA Cybersecurity Advisories
high
Botslab G980H Dashcams
Multiple vulnerabilities in Botslab G980H Dashcams could allow attackers to bypass authentication and gain unauthorized access.
Mentioned with
CVE-2026-75558 CVE-2026-77967 CVE-2026-82566 CVE-2026-82716 CVE-2026-84403 CVE-2026-85496 CVE-2026-88761
Also covered
- CVE-2026-86950 Apple iOS and iPadOS
- CVE-2023-6548 Cloud Software Group NetScaler ADC
- CVE-2023-25608 Fortinet FortiAP-W2
- CVE-2026-88772 Memory overflow vulnerability leading to Remote Code Execution or Denial of Service
- CVE-2026-88771 A remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commands