CVE-2026-82566
Deferred Deferred - Pending Action

Session Hijacking in Botslab G980H Dash Camera Firmware

Vulnerability report for CVE-2026-82566, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-24

Last updated on: 2026-09-24

Assigner: ICS-CERT

Description

The Botslab G980H dash camera firmware contains a session management vulnerability in which authentication state can remain valid after the associated client connection has been terminated or replaced. Under certain connection conditions, a newly established connection can displace an existing client while previously established session state remains active until a separate expiration mechanism invalidates it. An unauthenticated attacker with adjacent network access could potentially take advantage of this residual authentication state to access functionality associated with another client's session.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-24
Last Modified
2026-09-24
Generated
2026-09-25
AI Q&A
2026-09-25
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
botslab g980h_firmware *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-613 According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Botslab G980H dash camera firmware has a session management flaw where authentication remains valid even after the client connection ends or is replaced. This means a new connection can take over while the old session state lingers until it expires. An attacker on the same network could exploit this to access another user's session without authentication.

Impact Analysis

If exploited, an attacker could gain unauthorized access to the dash camera's functions, potentially viewing or manipulating recorded data, disabling features, or using the device as a pivot point to access other connected systems on the network.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating privacy requirements under GDPR and HIPAA. Organizations using this device may face compliance failures, legal penalties, and reputational damage due to potential data breaches.

Mitigation Strategies

Update the Botslab G980H dash camera firmware to the latest version to address the session management vulnerability. Ensure network segmentation to limit adjacent network access to the device. Monitor active sessions and terminate any suspicious or unauthorized connections immediately.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82566. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart