CVE-2026-77967: Botslab G980H Dashcams Authentication Bypass by Capture-replay
The Botslab G980H dash camera firmware accepts a reusable authentication value without adequately verifying its freshness or association with the requesting client. An unauthenticated attacker with adjacent network access who captures a valid authentication value could replay it from another client to establish an authenticated session and access privileged device functionality.
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Botslab G980H dashcams are exposed when an attacker has adjacent network access and can capture a valid authentication value exchanged by the device.
What must an attacker do to exploit the vulnerability?
The attacker must capture a valid authentication value and replay it from a different client. No prior authentication or user interaction is required.
What access could a successful attacker obtain?
A successful replay establishes an authenticated session, allowing access to privileged device functionality. The reported impact includes high confidentiality and integrity impact, with no availability impact indicated.