{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/botslab/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["G980H Dashcams (30010_QHG980HN5294SysFW+)","G980H Dashcams (58_QHG980HMCN5291SysFW+)"],"_cs_severities":["high"],"_cs_tags":["ics","firmware-vulnerability","transportation"],"_cs_type":"advisory","_cs_vendors":["Botslab"],"content_html":"\u003cp\u003eBotslab G980H dash cameras (versions 30010_QHG980HN5294SysFW+ and 58_QHG980HMCN5291SysFW+) are impacted by a significant set of 14 vulnerabilities, including CVE-2026-84399, CVE-2026-82566, CVE-2026-85496, CVE-2026-77967, CVE-2026-88761, CVE-2026-82716, CVE-2026-84403, CVE-2026-75558, CVE-2026-81630, CVE-2026-87118, CVE-2026-82708, CVE-2026-79959, CVE-2026-82585, and CVE-2026-88956. These flaws stem from poor implementation of authorization and session management within the firmware.\u003c/p\u003e\n\u003cp\u003eDefenders should note that the vendor has not provided patches for these issues. The vulnerabilities allow an unauthenticated attacker located on an adjacent network to intercept sessions, guess session identifiers, or replay authentication tokens to execute unauthorized commands. The scope of impact is broad, potentially affecting any transportation sector organization using these specific camera models globally. Because these devices serve as sensitive recording equipment, successful exploitation poses a severe risk to both operational privacy and device integrity.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an attacker to bypass authentication, access sensitive captured data, modify device configurations, and disrupt device operation. These vulnerabilities affect the Transportation Systems critical infrastructure sector globally. Given the lack of vendor response or remediation, affected devices currently remain in an unpatched, vulnerable state.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately isolate Botslab G980H dash cameras from public-facing or untrusted adjacent networks to prevent unauthorized remote access.\u003c/li\u003e\n\u003cli\u003eImplement strict network segmentation to ensure these devices cannot communicate with unauthorized endpoints.\u003c/li\u003e\n\u003cli\u003eMonitor network traffic originating from or destined to Botslab G980H hardware for anomalous authentication patterns or unauthorized API requests.\u003c/li\u003e\n\u003cli\u003eContact Botslab directly for updates regarding the availability of firmware patches as no official mitigation or update currently exists.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-24T16:14:25Z","date_published":"2026-09-24T16:14:25Z","id":"https://feed.craftedsignal.io/briefs/2026-09-botslab-dashcam-vulnerabilities/","summary":"Botslab G980H dash cameras are impacted by 14 firmware vulnerabilities allowing unauthenticated adjacent network attackers to bypass authentication, hijack sessions, and gain full control over device functionality.","title":"Multiple Vulnerabilities in Botslab G980H Dashcams","url":"https://feed.craftedsignal.io/briefs/2026-09-botslab-dashcam-vulnerabilities/"}],"language":"en","title":"CraftedSignal Threat Feed - Botslab","version":"https://jsonfeed.org/version/1.1"}