CVE-2026-81630: Botslab G980H Dashcams Insufficient Verification of Data Authenticity

Published Sep 24, 2026
·
Updated

The Botslab G980H dash camera firmware does not adequately verify the authenticity of firmware updates. The update process retrieves firmware through an unprotected connection and relies on an integrity value supplied with the firmware instead of a trusted cryptographic signature. A suitably positioned attacker who intercepts a firmware download, or an authenticated attacker who submits a crafted update, could install modified firmware and execute unauthorized code on the device.

Affected Software

1 affected component
Botslab G980H Dashcams

Event History

Sep 24, 2026
CVE Published
via MITRE·08:14 PM
Data Sourced
via MITRE·08:14 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:18 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to exploitation?

Devices are exposed when an attacker can intercept the firmware download path, or when an attacker is authenticated and able to submit a crafted update. Network interception requires the attacker to be suitably positioned to tamper with the unprotected connection.

2

Does exploitation require an existing account or user interaction?

No user interaction is required. Authentication is not required for an attacker who can intercept the firmware download, but it is required for the crafted-update attack path.

3

What is the impact of a successful attack?

An attacker could install modified firmware and execute unauthorized code on the dash camera. The reported impact includes high confidentiality, integrity, and availability effects.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203