Botslab G980H 行车记录仪固件接受可重复使用的认证值,但未充分验证其新鲜性或与请求客户端的关联关系。拥有相邻网络访问权限且未经认证的攻击者,若能捕获有效的认证值,则可将其从另一客户端重放,从而建立已认证会话并访问设备的特权功能。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82566 | 8.8 HIGH | Botslab G980H Dashcams Insufficient session expiration |
| CVE-2026-85496 | 8.8 HIGH | Botslab G980H Dashcams Generation of Predictable Numbers or Identifiers |
| CVE-2026-84399 | 8.8 HIGH | Botslab G980H Dashcams Incorrect Authorization |
| CVE-2026-81630 | 8.1 HIGH | Botslab G980H Dashcams Insufficient Verification of Data Authenticity |
| CVE-2026-88956 | 6.8 MEDIUM | Botslab G980H Dashcams Missing Authentication for Critical Function |
| CVE-2026-79959 | 6.8 MEDIUM | Botslab G980H Dashcams Use of Hard-coded Credentials |
| CVE-2026-82585 | 6.5 MEDIUM | Botslab G980H Dashcams Cleartext Transmission of Sensitive Information |
| CVE-2026-82708 | 6.5 MEDIUM | Botslab G980H Dashcams Improper Limitation of a Pathname to a Restricted Directory |
| CVE-2026-84403 | 6.2 MEDIUM | Botslab G980H Dashcams Missing Authentication for Critical Function |
| CVE-2026-87118 | 5.7 MEDIUM | Botslab G980H Dashcams Out-of-bounds Write |
| CVE-2026-75558 | 5.3 MEDIUM | Botslab G980H Dashcams Use of Hard-coded Cryptographic Key |
| CVE-2026-88761 | 5.3 MEDIUM | Botslab G980H Dashcams Use of Weak Credentials |
| CVE-2026-82716 | 4.6 MEDIUM | Botslab G980H Dashcams Insertion of Sensitive Information into Log File |
No comments yet