CVE-2026-82708
Deferred Deferred - Pending Action

Path Traversal in Botslab G980H Dash Camera Firmware

Vulnerability report for CVE-2026-82708, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-24

Last updated on: 2026-09-24

Assigner: ICS-CERT

Description

The Botslab G980H dash camera firmware contains a path traversal vulnerability in its HTTP server. An attacker with access to the device's WiFi network could submit a crafted request to access files within the device's removable storage that were not intended to be directly accessible through the web server. Exposed files could include recordings, images, diagnostic logs, or firmware files.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-24
Last Modified
2026-09-24
Generated
2026-09-25
AI Q&A
2026-09-25
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
botslab g980h_firmware *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Botslab G980H dash camera firmware has a path traversal vulnerability in its HTTP server. An attacker on the device's WiFi network can send a specially crafted request to access files in the removable storage that should not be directly accessible via the web server. This could expose sensitive data like recordings, images, logs, or firmware files.

Detection Guidance

To detect this vulnerability, scan your network for the Botslab G980H dash camera and check if the HTTP server is accessible. Use tools like nmap to identify the device and test for path traversal by sending crafted requests to access files outside the intended web directory.

Impact Analysis

An attacker could steal sensitive data such as recordings or images, access diagnostic logs for further attacks, or extract firmware files to analyze for additional vulnerabilities. This could lead to privacy breaches or unauthorized control of the device.

Compliance Impact

This vulnerability could lead to unauthorized access to personal or sensitive data, violating GDPR (data protection) and HIPAA (health information privacy) requirements. Organizations may face legal penalties, fines, or reputational damage due to non-compliance.

Mitigation Strategies

Immediately disconnect the device from your network or disable its WiFi interface. Update the firmware if a patch is available. If no patch exists, restrict network access to the device and monitor for suspicious activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82708. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart