CVE-2026-82566: Botslab g980h

High severity, CVSS 8.8. EPSS: 0.3% chance of exploitation in the next 30 days.

The Botslab G980H dash camera firmware contains a session management vulnerability in which authentication state can remain valid after the associated client connection has been terminated or replaced. Under certain connection conditions, a newly established connection can displace an existing client while previously established session state remains active until a separate expiration mechanism invalidates it. An unauthenticated attacker with adjacent network access could potentially take advantage of this residual authentication state to access functionality associated with another client's session.

Affected products

  • Botslab g980h: from 30010_QHG980HN5294SysFW; from 58_QHG980HMCN5291SysFW

Published 2026-09-24. Last modified 2026-09-24.