CVE-2026-82716: Botslab G980H Dashcams Insertion of Sensitive Information into Log File
The Botslab G980H dash camera firmware includes sensitive configuration information, including WiFi credentials, in diagnostic logs generated during the support process. These logs remain accessible on removable storage after the support operation has completed. An unauthenticated attacker with physical access to the storage media could retrieve the logs and obtain sensitive device information.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Botslab G980H dash camera users who generate diagnostic logs during the support process are exposed if the resulting removable storage can be physically accessed by an unauthorized person.
What does an attacker need to exploit it?
An attacker does not need authentication, but must obtain physical access to the removable storage containing the diagnostic logs. The logs may disclose WiFi credentials and other sensitive device configuration information.
Are devices affected during normal operation by default?
The described exposure is tied to diagnostic logs generated during the support process. The provided information does not establish that sensitive logs are created or left accessible during ordinary operation.
What can be done if no patch is available?
Treat removable storage used for support diagnostics as sensitive, restrict physical access to it, and remove or securely erase diagnostic logs after support operations are complete.