CVE-2026-84403: Botslab G980H Dashcams Missing Authentication for Critical Function
The Botslab G980H dash camera firmware does not require authenticated pairing or client binding before permitting access to Bluetooth Low Energy communications and GATT characteristics. An unauthenticated attacker within Bluetooth range could intercept or directly retrieve sensitive device information, including device identifiers, firmware information, and protected WiFi credentials.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An unauthenticated attacker only needs to be within Bluetooth Low Energy range of a Botslab G980H dashcam. No prior pairing, client binding, or user interaction is required.
What information could be exposed?
An attacker may intercept or directly retrieve sensitive information exposed through BLE and GATT characteristics, including device identifiers, firmware information, and protected WiFi credentials.
Is a particular configuration required for exposure?
The affected firmware permits BLE and GATT access without authenticated pairing or client binding. The available information does not identify any additional configuration requirement.