CVE-2026-84403
Deferred Deferred - Pending Action

Unauthenticated Bluetooth Access in Botslab G980H Dash Camera Firmware

Vulnerability report for CVE-2026-84403, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-24

Last updated on: 2026-09-24

Assigner: ICS-CERT

Description

The Botslab G980H dash camera firmware does not require authenticated pairing or client binding before permitting access to Bluetooth Low Energy communications and GATT characteristics. An unauthenticated attacker within Bluetooth range could intercept or directly retrieve sensitive device information, including device identifiers, firmware information, and protected WiFi credentials.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-24
Last Modified
2026-09-24
Generated
2026-09-25
AI Q&A
2026-09-25
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
botslab g980h_firmware *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Botslab G980H dash camera firmware lacks authentication for Bluetooth Low Energy (BLE) communications. This allows an attacker within Bluetooth range to access sensitive data without pairing or binding, including device identifiers, firmware details, and WiFi credentials.

Detection Guidance

This vulnerability involves unauthenticated Bluetooth Low Energy access to the Botslab G980H dash camera. Detection requires checking for unauthorized Bluetooth connections or unusual data transmission from the device. Use Bluetooth scanning tools like hcitool or bluetoothctl to monitor nearby devices and inspect GATT characteristics for unexpected access.

Impact Analysis

An attacker could intercept sensitive information like device IDs, firmware data, or WiFi credentials. This may lead to unauthorized access to the camera's network or device-specific data, potentially compromising privacy or enabling further attacks.

Compliance Impact

This vulnerability could violate data protection requirements under GDPR or HIPAA by exposing personally identifiable information or sensitive data without proper authentication. Organizations may face compliance penalties if such breaches occur.

Mitigation Strategies

Disable Bluetooth on the device if not in use. Update the firmware to the latest version if an authenticated pairing mechanism is available. Restrict physical access to the device to prevent unauthorized Bluetooth range attacks. Monitor network traffic for unusual data exfiltration from the camera.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-84403. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart