CVE-2026-84399
Deferred Deferred - Pending Action

Authorization Bypass in Botslab G980H Firmware

Vulnerability report for CVE-2026-84399, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-24

Last updated on: 2026-09-24

Assigner: ICS-CERT

Description

The Botslab G980H dash camera firmware contains an authorization vulnerability in its session based command functionality. The product does not sufficiently associate an authenticated session with the client connection that established it, and subsequent privileged operations rely on possession of a valid session identifier without adequately validating the requesting client's authenticated context. An unauthenticated attacker with adjacent network access could potentially use valid session state associated with another client to access privileged functionality.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-24
Last Modified
2026-09-24
Generated
2026-09-25
AI Q&A
2026-09-25
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
botslab g980h_firmware *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Botslab G980H dash camera firmware has an authorization vulnerability where session-based commands are not properly tied to the authenticated client. This allows an attacker with adjacent network access to use a valid session from another client to perform privileged actions without proper validation.

Impact Analysis

An attacker could gain unauthorized access to privileged functions of the dash camera, potentially viewing, modifying, or deleting sensitive data. This includes accessing live feeds, stored recordings, or camera settings without authentication.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating privacy and security requirements under GDPR and HIPAA. Organizations using this device may face compliance violations, legal penalties, and reputational damage.

Mitigation Strategies

Immediately update the Botslab G980H dash camera firmware to the latest version provided by the vendor to address the authorization vulnerability. Ensure network segmentation to limit adjacent network access to the device. Monitor network traffic for unusual session-based command activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-84399. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart