CVE-2026-84403
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Summary
The Botslab G980H dash camera firmware does not require authenticated pairing or client binding before permitting access to Bluetooth Low Energy communications and GATT characteristics. An unauthenticated attacker within Bluetooth range could intercept or directly retrieve sensitive device information, including device identifiers, firmware information, and protected WiFi credentials.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Botslab | G980H | 30010_QHG980HN5294SysFW+ | affected |
| Botslab | G980H | 58_QHG980HMCN5291SysFW+ | affected |
Weaknesses
- CWE-306: CWE-306 Missing authentication for critical function
Workarounds
Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information: https://www.botslab.com/pages/about-botslab
References
- https://www.botslab.com/pages/about-botslab
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-267-01
- https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-267-01.json
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.