Machine-generated analysis · WAYSCloud LLM
Botslab G980H dashcams (firmware series 30010_QHG980HN5294SysFW+ and 58_QHG980HMCN5291SysFW+) are identified as vulnerable. The advisory notes multiple CVEs allowing authentication bypass and device manipulation.
Context
The advisory concerns Botslab G980H dashcams, specifically firmware series 30010_QHG980HN5294SysFW+ and 58_QHG980HMCN5291SysFW+. It states that the vulnerabilities could let an attacker bypass authentication, access sensitive data, modify configuration, and disrupt operation. The devices are deployed worldwide in transportation systems. The listed weaknesses include improper session handling, hard-coded credentials, and path-traversal flaws.
Operator considerations
Check: Verify the installed firmware version against the affected series.
Isolate: Place dashcams on a segregated network segment or restrict management traffic.
Log: Record attempts to use session identifiers or access privileged functions.
Successful exploitation of these vulnerabilities could allow an attacker to bypass authentication controls, gain unauthorized access to sensitive data and privileged device functionality, modify device configuration, disrupt device operation.
The following versions of Botslab G980H Dashcams are affected:
G980H dash cam series 30010_QHG980HN5294SysFW+ (CVE-2026-84399, CVE-2026-82566, CVE-2026-85496, CVE-2026-77967, CVE-2026-88761, CVE-2026-82716, CVE-2026-84403, CVE-2026-75558, CVE-2026-81630, CVE-2026-87118, CVE-2026-82708, CVE-2026-79959, CVE-2026-82585)
G980H dash cam series 58_QHG980HMCN5291SysFW+ (CVE-2026-84399, CVE-2026-82566, CVE-2026-85496, CVE-2026-77967, CVE-2026-88761, CVE-2026-88956, CVE-2026-82716, CVE-2026-84403, CVE-2026-75558, CVE-2026-81630, CVE-2026-87118, CVE-2026-82708, CVE-2026-82585)
Vendor
Equipment
Botslab
Botslab G980H Dashcams
Incorrect Authorization,...
Read the full advisory on CISA →