CISA Flags Multiple Critical Vulnerabilities in Botslab G980H Dashcams
CISA has identified numerous critical vulnerabilities in Botslab G980H dashcams, enabling unauthenticated attackers to bypass security and disrupt operations.

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a stern warning regarding multiple critical vulnerabilities discovered in Botslab G980H dashcams. These security flaws, detailed in CISA advisory ICSA-26-267-01, pose a significant risk to transportation systems globally, as they allow unauthenticated attackers with adjacent network access to bypass authentication, gain unauthorized access, modify configurations, and potentially disrupt device operations.
The vulnerabilities affect specific firmware versions of the G980H dash cam series, namely 30010_QHG980HN5294SysFW+ and 58_QHG980HMCN5291SysFW+. The identified flaws include issues such as Incorrect Authorization, Insufficient Session Expiration, Generation of Predictable Numbers or Identifiers, Authentication Bypass by Capture-replay, Use of Weak Credentials, and Missing Authentication for Critical Functions. The collective impact of these vulnerabilities is rated with a high CVSS v3.1 score of 8.8, indicating a severe security risk.
One of the primary concerns highlighted is CVE-2026-84399, an authorization vulnerability within the dashcam's session-based command functionality. This flaw means the product does not adequately associate an authenticated session with the client connection that initiated it. Consequently, an attacker could potentially leverage a valid session identifier belonging to another client to access privileged functions, even without proper authentication.
Another critical vulnerability, CVE-2026-82566, relates to insufficient session expiration. This allows authentication state to remain valid even after the associated client connection has been terminated or replaced. An attacker could exploit this residual authentication state to hijack an existing session and gain unauthorized access to device functionalities.
Furthermore, CVE-2026-85496 points to the generation of predictable session identifiers. By using a limited, sequential value space for session IDs instead of a truly unpredictable source, attackers can potentially guess or determine valid session identifiers, thereby bypassing authentication controls.
Other identified vulnerabilities include CVE-2026-77967 (Authentication Bypass by Capture-replay), where an attacker could replay captured authentication values; CVE-2026-88761 (Use of Weak Credentials); and CVE-2026-82716 (Missing Authentication for Critical Function), among others. The breadth of these vulnerabilities suggests a systemic weakness in the device's security architecture.
Botslab, the manufacturer of the affected dashcams, has not yet provided any official mitigations or patches for these vulnerabilities. CISA notes that Botslab has not responded to requests to work with the agency on addressing these security issues. Users of the affected G980H Dashcam models are advised to contact Botslab directly for further information, though no immediate solutions are available. The advisory emphasizes that these devices are deployed worldwide, particularly within transportation systems, making the potential impact of exploitation significant.
Given the lack of vendor response and the critical nature of the vulnerabilities, CISA urges users to exercise caution. The agency recommends that organizations using these devices review the advisory thoroughly and consider potential workarounds or enhanced network segmentation if possible, while awaiting vendor-provided security updates.