CVE-2026-82708: Botslab G980H Dashcams Improper Limitation of a Pathname to a Restricted Directory
The Botslab G980H dash camera firmware contains a path traversal vulnerability in its HTTP server. An attacker with access to the device's WiFi network could submit a crafted request to access files within the device's removable storage that were not intended to be directly accessible through the web server. Exposed files could include recordings, images, diagnostic logs, or firmware files.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs access to the dashcam's WiFi network. No authentication or user interaction is required according to the supplied severity vector.
What data could be exposed?
Crafted HTTP requests may access files on removable storage that the web server was not intended to expose. This can include recordings, images, diagnostic logs, and firmware files.
Does this vulnerability allow modification or deletion of files?
The provided information describes unauthorized file access and rates confidentiality impact as high. It does not indicate integrity or availability impact, so modification or deletion is not established by the available data.