CVE-2026-84399 Details
Description
The Botslab G980H dash camera firmware contains an authorization vulnerability in its session based command functionality. The product does not sufficiently associate an authenticated session with the client connection that established it, and subsequent privileged operations rely on possession of a valid session identifier without adequately validating the requesting client's authenticated context. An unauthenticated attacker with adjacent network access could potentially use valid session state associated with another client to access privileged functionality.
An authorization vulnerability has been identified in the Botslab G980H dash camera firmware, specifically in the session-based command functionality. The issue arises because the product fails to properly associate an authenticated session with the client connection that initiated it. As a result, subsequent privileged operations can be performed using a valid session identifier without adequately verifying the authenticated context of the requesting client. This vulnerability could allow an unauthenticated attacker with adjacent network access to exploit valid session states linked to other clients, gaining access to privileged features.
Botslab has not responded to requests to collaborate with CISA on mitigating this vulnerability. Users of the affected G980H dash cam series are encouraged to contact Botslab for more information.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 24, 2026CISA-ADP
Assessed Sep 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-267-01.json | [email protected] | AdvisoryBundlePartial Content |
| https://www.cisa.gov/news-events/ics-advisories/icsa-26-267-01 | [email protected] | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Botslab G980H | G980H dash cam series 30010_QHG980HN5294SysFW+ G980H dash cam series 58_QHG980HMCN5291SysFW+ |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 24, 2026 | New CVE Received | [email protected] |
| Sep 24, 2026 | CVE Modified | CISA-ADP |
Volerion