CVE-2026-84403: Botslab g980h

Medium severity, CVSS 6.2. EPSS: 0.1% chance of exploitation in the next 30 days.

The Botslab G980H dash camera firmware does not require authenticated pairing or client binding before permitting access to Bluetooth Low Energy communications and GATT characteristics. An unauthenticated attacker within Bluetooth range could intercept or directly retrieve sensitive device information, including device identifiers, firmware information, and protected WiFi credentials.

Affected products

  • Botslab g980h: from 30010_QHG980HN5294SysFW; from 58_QHG980HMCN5291SysFW

Published 2026-09-24. Last modified 2026-09-25.