CVE-2026-85496: Botslab g980h
High severity, CVSS 8.8. EPSS: 0.3% chance of exploitation in the next 30 days.
The Botslab G980H dash camera firmware generates session identifiers using a small sequential value space rather than a suitably unpredictable source. An unauthenticated attacker with adjacent network access and knowledge that an active session exists could potentially determine a valid session identifier and use it to bypass intended authorization controls.
Affected products
- Botslab g980h: from 30010_QHG980HN5294SysFW; from 58_QHG980HMCN5291SysFW
Published 2026-09-24. Last modified 2026-09-25.