Botslab G980H 行车记录仪固件中包含一个硬编码的 root 账户密码,且该密码无法由用户更改。攻击者若能获取该固件或对设备具有物理访问权限,即可恢复该凭据,并通过 UART 接口获得 root 访问权限。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82566 | 8.8 HIGH | Botslab G980H Dashcams Insufficient session expiration |
| CVE-2026-85496 | 8.8 HIGH | Botslab G980H Dashcams Generation of Predictable Numbers or Identifiers |
| CVE-2026-84399 | 8.8 HIGH | Botslab G980H Dashcams Incorrect Authorization |
| CVE-2026-77967 | 8.1 HIGH | Botslab G980H Dashcams Authentication Bypass by Capture-replay |
| CVE-2026-81630 | 8.1 HIGH | Botslab G980H Dashcams Insufficient Verification of Data Authenticity |
| CVE-2026-88956 | 6.8 MEDIUM | Botslab G980H Dashcams Missing Authentication for Critical Function |
| CVE-2026-82585 | 6.5 MEDIUM | Botslab G980H Dashcams Cleartext Transmission of Sensitive Information |
| CVE-2026-82708 | 6.5 MEDIUM | Botslab G980H Dashcams Improper Limitation of a Pathname to a Restricted Directory |
| CVE-2026-84403 | 6.2 MEDIUM | Botslab G980H Dashcams Missing Authentication for Critical Function |
| CVE-2026-87118 | 5.7 MEDIUM | Botslab G980H Dashcams Out-of-bounds Write |
| CVE-2026-75558 | 5.3 MEDIUM | Botslab G980H Dashcams Use of Hard-coded Cryptographic Key |
| CVE-2026-88761 | 5.3 MEDIUM | Botslab G980H Dashcams Use of Weak Credentials |
| CVE-2026-82716 | 4.6 MEDIUM | Botslab G980H Dashcams Insertion of Sensitive Information into Log File |
No comments yet