CVE-2026-85496
Deferred Deferred - Pending Action

Session ID Prediction in Botslab G980H Dash Camera Firmware

Vulnerability report for CVE-2026-85496, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-24

Last updated on: 2026-09-24

Assigner: ICS-CERT

Description

The Botslab G980H dash camera firmware generates session identifiers using a small sequential value space rather than a suitably unpredictable source. An unauthenticated attacker with adjacent network access and knowledge that an active session exists could potentially determine a valid session identifier and use it to bypass intended authorization controls.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-24
Last Modified
2026-09-24
Generated
2026-09-25
AI Q&A
2026-09-25
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-340 The product uses a scheme that generates numbers or identifiers that are more predictable than required.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Botslab G980H dash camera firmware creates session identifiers using a small sequential number range instead of a random unpredictable value. An attacker within nearby network range who knows an active session exists could guess the session ID and use it to bypass security controls without authentication.

Impact Analysis

An attacker could hijack active sessions to gain unauthorized access to the dash camera system, potentially viewing or altering recorded footage, disabling features, or using the device as a foothold to attack other connected systems.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data stored or transmitted by the dash camera, violating confidentiality requirements in GDPR and HIPAA. Organizations may face compliance violations and penalties due to insufficient session security.

Mitigation Strategies

Immediately update the Botslab G980H dash camera firmware to the latest version if an update is available. Disable any unnecessary network services on the device to reduce exposure. Monitor network traffic for unusual session activity or unauthorized access attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-85496. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart