<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Botslab - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/botslab/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 24 Sep 2026 16:14:25 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/botslab/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Multiple Vulnerabilities in Botslab G980H Dashcams</title><link>https://feed.craftedsignal.io/briefs/2026-09-botslab-dashcam-vulnerabilities/</link><pubDate>Thu, 24 Sep 2026 16:14:25 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-botslab-dashcam-vulnerabilities/</guid><description>Botslab G980H dash cameras are impacted by 14 firmware vulnerabilities allowing unauthenticated adjacent network attackers to bypass authentication, hijack sessions, and gain full control over device functionality.</description><content:encoded><![CDATA[<p>Botslab G980H dash cameras (versions 30010_QHG980HN5294SysFW+ and 58_QHG980HMCN5291SysFW+) are impacted by a significant set of 14 vulnerabilities, including CVE-2026-84399, CVE-2026-82566, CVE-2026-85496, CVE-2026-77967, CVE-2026-88761, CVE-2026-82716, CVE-2026-84403, CVE-2026-75558, CVE-2026-81630, CVE-2026-87118, CVE-2026-82708, CVE-2026-79959, CVE-2026-82585, and CVE-2026-88956. These flaws stem from poor implementation of authorization and session management within the firmware.</p>
<p>Defenders should note that the vendor has not provided patches for these issues. The vulnerabilities allow an unauthenticated attacker located on an adjacent network to intercept sessions, guess session identifiers, or replay authentication tokens to execute unauthorized commands. The scope of impact is broad, potentially affecting any transportation sector organization using these specific camera models globally. Because these devices serve as sensitive recording equipment, successful exploitation poses a severe risk to both operational privacy and device integrity.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows an attacker to bypass authentication, access sensitive captured data, modify device configurations, and disrupt device operation. These vulnerabilities affect the Transportation Systems critical infrastructure sector globally. Given the lack of vendor response or remediation, affected devices currently remain in an unpatched, vulnerable state.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Immediately isolate Botslab G980H dash cameras from public-facing or untrusted adjacent networks to prevent unauthorized remote access.</li>
<li>Implement strict network segmentation to ensure these devices cannot communicate with unauthorized endpoints.</li>
<li>Monitor network traffic originating from or destined to Botslab G980H hardware for anomalous authentication patterns or unauthorized API requests.</li>
<li>Contact Botslab directly for updates regarding the availability of firmware patches as no official mitigation or update currently exists.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>ics</category><category>firmware-vulnerability</category><category>transportation</category></item></channel></rss>