CVE-2026-81630: Botslab G980H Dashcams Insufficient Verification of Data Authenticity
The Botslab G980H dash camera firmware does not adequately verify the authenticity of firmware updates. The update process retrieves firmware through an unprotected connection and relies on an integrity value supplied with the firmware instead of a trusted cryptographic signature. A suitably positioned attacker who intercepts a firmware download, or an authenticated attacker who submits a crafted update, could install modified firmware and execute unauthorized code on the device.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to exploitation?
Devices are exposed when an attacker can intercept the firmware download path, or when an attacker is authenticated and able to submit a crafted update. Network interception requires the attacker to be suitably positioned to tamper with the unprotected connection.
Does exploitation require an existing account or user interaction?
No user interaction is required. Authentication is not required for an attacker who can intercept the firmware download, but it is required for the crafted-update attack path.
What is the impact of a successful attack?
An attacker could install modified firmware and execute unauthorized code on the dash camera. The reported impact includes high confidentiality, integrity, and availability effects.