CVE-2026-79959
7
CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Summary
The Botslab G980H dash camera firmware contains a hard-coded root account password that cannot be changed by the user. An attacker who obtains the firmware or has physical access to the device could recover the credential and use it to obtain root access through the UART interface.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Botslab | G980H | 30010_QHG980HN5294SysFW+ | affected |
| Botslab | G980H | 58_QHG980HMCN5291SysFW+ | affected |
Weaknesses
- CWE-798: CWE-798
Workarounds
Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information: https://www.botslab.com/pages/about-botslab
References
- https://www.botslab.com/pages/about-botslab
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-267-01
- https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-267-01.json
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.