Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information: https://www.botslab.com/pages/about-botslab
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 24 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 24 Sep 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Botslab G980H dash camera firmware contains a session management vulnerability in which authentication state can remain valid after the associated client connection has been terminated or replaced. Under certain connection conditions, a newly established connection can displace an existing client while previously established session state remains active until a separate expiration mechanism invalidates it. An unauthenticated attacker with adjacent network access could potentially take advantage of this residual authentication state to access functionality associated with another client's session. | |
| Title | Botslab G980H Dashcams Insufficient session expiration | |
| Weaknesses | CWE-613 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-09-24T19:37:00.841Z
Reserved: 2026-09-10T15:31:03.065Z
Link: CVE-2026-82566
Updated: 2026-09-24T19:36:56.192Z
Status : Received
Published: 2026-09-24T20:17:32.503
Modified: 2026-09-24T20:17:32.503
Link: CVE-2026-82566
No data.
OpenCVE Enrichment
No data.
-
CWE-613
Insufficient Session Expiration