CVE-2026-88956
Deferred Deferred - Pending Action

Authentication Bypass in Botslab G980H Firmware

Vulnerability report for CVE-2026-88956, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-24

Last updated on: 2026-09-24

Assigner: ICS-CERT

Description

The Botslab G980H dash camera firmware contains an authentication vulnerability in the root account exposed through the device's UART interface. The affected account does not require a password before granting access to a privileged system interface, and the interface also displays the device's WiFi password during startup. An unauthenticated attacker with physical access to the device could connect to the UART interface, obtain root privileges, and recover the WiFi password.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-24
Last Modified
2026-09-24
Generated
2026-09-25
AI Q&A
2026-09-25
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
botslab g980h_firmware *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Botslab G980H dash camera firmware has an authentication flaw in its root account accessible via the device's UART interface. This account does not require a password, allowing full privileged access. Additionally, the device's WiFi password is displayed during startup.

Detection Guidance

Check for unauthorized physical access to the device's UART interface. Inspect firmware logs for WiFi password exposure during startup. No specific commands are provided in the context.

Impact Analysis

An attacker with physical access could exploit this to gain root privileges, access sensitive system functions, and retrieve the WiFi password. This could lead to unauthorized network access or further attacks on connected systems.

Mitigation Strategies

Disable or secure the UART interface physically. Update firmware if a patch is available. Restrict physical access to the device. Monitor for unauthorized access attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-88956. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart