AllCyberNews

CVE-2026-84399

Botslab G980H Dashcams Incorrect Authorization

CVSS 8.7 high · Botslab G980H · published 2026-09-24

The Botslab G980H dash camera firmware contains an authorization vulnerability in its session based command functionality. The product does not sufficiently associate an authenticated session with the client connection that established it, and subsequent privileged operations rely on possession of a valid session identifier without adequately validating the requesting client's authenticated context. An unauthenticated attacker with adjacent network access could potentially use valid session state associated with another client to access privileged functionality.

Coverage 1 source

  1. 2026-09-24 CISA Cybersecurity Advisories high Botslab G980H Dashcams

    Multiple vulnerabilities in Botslab G980H Dashcams could allow attackers to bypass authentication and gain unauthorized access.

Mentioned with

CVE-2026-75558 CVE-2026-77967 CVE-2026-82566 CVE-2026-82716 CVE-2026-84403 CVE-2026-85496 CVE-2026-88761

Also covered