CVE-2026-82585 Details
Description
The Botslab G980H dash camera firmware transmits sensitive information over unencrypted HTTP and RTSP connections. An attacker capable of intercepting communications on the device's WiFi network could obtain stored recordings, live video, location information, images, diagnostic logs, or other sensitive information exchanged between the device and its mobile application.
A vulnerability exists in the Botslab G980H dash camera firmware, which transmits sensitive information over unencrypted HTTP and RTSP connections. This flaw allows an attacker to intercept communications on the device's WiFi network and access stored recordings, live video, location data, images, diagnostic logs, and other sensitive information exchanged between the camera and its mobile application.
Botslab has not responded to requests to collaborate with CISA on mitigating this vulnerability. Users of affected G980H dash cameras are encouraged to contact Botslab for more information.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-267-01.json | [email protected] | AdvisoryBundleRemedy |
| https://www.botslab.com/pages/about-botslab | [email protected] | Vendor |
| https://www.cisa.gov/news-events/ics-advisories/icsa-26-267-01 | [email protected] | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-319 | Cleartext Transmission of Sensitive Information | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Botslab G980H | G980H dash cam series 30010_QHG980HN5294SysFW+ G980H dash cam series 58_QHG980HMCN5291SysFW+ |
CPE
Remediation
| |
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 24, 2026 | New CVE Received | [email protected] |
Volerion