CVE-2026-84403 Details
Description
The Botslab G980H dash camera firmware does not require authenticated pairing or client binding before permitting access to Bluetooth Low Energy communications and GATT characteristics. An unauthenticated attacker within Bluetooth range could intercept or directly retrieve sensitive device information, including device identifiers, firmware information, and protected WiFi credentials.
A vulnerability in the Botslab G980H dash camera firmware allows unauthenticated access to Bluetooth Low Energy communications and GATT characteristics. This issue arises because the firmware does not require authenticated pairing or client binding before granting access. An unauthenticated attacker within Bluetooth range could intercept or directly retrieve sensitive device information, such as device identifiers, firmware details, and protected WiFi credentials.
Botslab has not responded to requests to mitigate this vulnerability. Users are invited to contact Botslab for more information.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-267-01.json | [email protected] | AdvisoryBundleRemedy |
| https://www.botslab.com/pages/about-botslab | [email protected] | Vendor |
| https://www.cisa.gov/news-events/ics-advisories/icsa-26-267-01 | [email protected] | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Botslab G980H | G980H dash cam series 30010_QHG980HN5294SysFW+ G980H dash cam series 58_QHG980HMCN5291SysFW+ |
CPE
Remediation
| |
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 24, 2026 | New CVE Received | [email protected] |
Volerion