Botslab G980H 行车记录仪的固件更新机制在验证固件更新真实性方面存在不足。该更新过程通过未加密的连接下载固件,并且仅依赖固件附带的完整性校验值,而非使用可信的密码学签名进行验证。处于合适网络位置的攻击者若拦截固件下载过程,或已获授权但提交恶意构造的固件更新包的攻击者,均可安装被篡改的固件,从而在设备上执行未授权的代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82566 | 8.8 HIGH | Botslab G980H Dashcams Insufficient session expiration |
| CVE-2026-85496 | 8.8 HIGH | Botslab G980H Dashcams Generation of Predictable Numbers or Identifiers |
| CVE-2026-84399 | 8.8 HIGH | Botslab G980H Dashcams Incorrect Authorization |
| CVE-2026-77967 | 8.1 HIGH | Botslab G980H Dashcams Authentication Bypass by Capture-replay |
| CVE-2026-88956 | 6.8 MEDIUM | Botslab G980H Dashcams Missing Authentication for Critical Function |
| CVE-2026-79959 | 6.8 MEDIUM | Botslab G980H Dashcams Use of Hard-coded Credentials |
| CVE-2026-82585 | 6.5 MEDIUM | Botslab G980H Dashcams Cleartext Transmission of Sensitive Information |
| CVE-2026-82708 | 6.5 MEDIUM | Botslab G980H Dashcams Improper Limitation of a Pathname to a Restricted Directory |
| CVE-2026-84403 | 6.2 MEDIUM | Botslab G980H Dashcams Missing Authentication for Critical Function |
| CVE-2026-87118 | 5.7 MEDIUM | Botslab G980H Dashcams Out-of-bounds Write |
| CVE-2026-75558 | 5.3 MEDIUM | Botslab G980H Dashcams Use of Hard-coded Cryptographic Key |
| CVE-2026-88761 | 5.3 MEDIUM | Botslab G980H Dashcams Use of Weak Credentials |
| CVE-2026-82716 | 4.6 MEDIUM | Botslab G980H Dashcams Insertion of Sensitive Information into Log File |
No comments yet