CVE-2026-85496: Botslab G980H Dashcams Generation of Predictable Numbers or Identifiers
The Botslab G980H dash camera firmware generates session identifiers using a small sequential value space rather than a suitably unpredictable source. An unauthenticated attacker with adjacent network access and knowledge that an active session exists could potentially determine a valid session identifier and use it to bypass intended authorization controls.
Affected Software
Event History
Frequently Asked Questions
Who is realistically exposed to exploitation?
Devices with an active session are exposed to an unauthenticated attacker who has adjacent network access. The attacker must also know that an active session exists.
What does an attacker need to bypass authorization controls?
The attacker needs adjacent network access and knowledge of an active session. Because session identifiers come from a small sequential value space, they may be able to determine a valid identifier without authentication.
Is user interaction or prior authentication required?
No. The vulnerability is described as exploitable by an unauthenticated attacker and does not require user interaction.