CVE-2026-82585
Deferred Deferred - Pending Action

Botslab G980H Dash Camera Sensitive Data Exposure

Vulnerability report for CVE-2026-82585, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-24

Last updated on: 2026-09-24

Assigner: ICS-CERT

Description

The Botslab G980H dash camera firmware transmits sensitive information over unencrypted HTTP and RTSP connections. An attacker capable of intercepting communications on the device's WiFi network could obtain stored recordings, live video, location information, images, diagnostic logs, or other sensitive information exchanged between the device and its mobile application.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-24
Last Modified
2026-09-24
Generated
2026-09-25
AI Q&A
2026-09-25
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-319 The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Botslab G980H dash camera firmware sends sensitive data like recordings, live video, location, images, and logs over unencrypted HTTP and RTSP connections. An attacker on the same WiFi network could intercept this data.

Detection Guidance

To detect this vulnerability, monitor network traffic for unencrypted HTTP and RTSP connections from the Botslab G980H dash camera. Use packet sniffing tools like Wireshark or tcpdump to capture and analyze traffic on the device's WiFi network. Look for plaintext transmission of sensitive data such as recordings, location, or logs.

Impact Analysis

Attackers could access your stored recordings, live video feeds, location data, images, or diagnostic logs. This could lead to privacy violations, unauthorized surveillance, or misuse of sensitive information.

Compliance Impact

This vulnerability likely violates GDPR and HIPAA due to unauthorized exposure of personal and sensitive data. Organizations using this device may face compliance violations, legal penalties, and reputational damage.

Mitigation Strategies

Immediately stop using the device's WiFi network for sensitive operations. Update the firmware if a patch is available. Isolate the device on a separate network segment. Use a firewall to block unnecessary outbound connections. Consider replacing the device if no secure firmware update is provided.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82585. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart