www.cisa.gov 24 Sept 2026, 12:00 UTC

CISA Warns Botslab Dashcams Could Expose Video and Credentials

CyberSIXT Evidence Panel
CISA KEV Not in KEV
Patch Patch Status Unknown

CISA has warned that two firmware versions of Botslab’s G980H dashcams are affected by 13 vulnerabilities. The affected releases are 30010_QHG980HN5294SysFW+ and 58_QHG980HMCN5291SysFW+; the latter is affected by 12 of the listed CVEs. The flaws could allow attackers to bypass authentication, access sensitive data and privileged functions, alter configuration or disrupt operation.

The advisory covers issues including weak and reusable session credentials, predictable Wi-Fi passwords, unauthenticated Bluetooth Low Energy and UART access, hard-coded cryptographic keys and root credentials, path traversal, firmware-update integrity failures, out-of-bounds writes and unencrypted HTTP and RTSP traffic. Potentially exposed information includes recordings, live video, location data, images, diagnostic logs and Wi-Fi credentials.

The highest-rated issue is CVE-2026-81630, scored 8.1 under CVSS v3.1 and 9.2 under CVSS v4.0. It could enable a suitably positioned attacker to intercept a firmware download or an authenticated attacker to submit a crafted update and install modified firmware. Other vulnerabilities require adjacent network, Wi-Fi, Bluetooth, physical or authenticated access, depending on the flaw.

CISA says successful exploitation could have serious confidentiality, integrity and availability effects, but no known public exploitation specifically targeting these vulnerabilities had been reported as of 24 September 2026. Botslab had not responded to CISA’s requests to develop mitigations, so users are directed to contact the company for information about remediation.

View full article

Article by CyberSIXT