Botslab G980H 行车记录仪的固件在支持过程中生成的诊断日志中包含了敏感的配置信息,包括 Wi-Fi 凭证。这些日志在支持操作完成后仍保留在可移动存储介质上。未经认证的攻击者若具备对存储介质的物理访问权限,便可能获取这些日志,从而窃取设备的敏感信息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82566 | 8.8 HIGH | Botslab G980H Dashcams Insufficient session expiration |
| CVE-2026-85496 | 8.8 HIGH | Botslab G980H Dashcams Generation of Predictable Numbers or Identifiers |
| CVE-2026-84399 | 8.8 HIGH | Botslab G980H Dashcams Incorrect Authorization |
| CVE-2026-77967 | 8.1 HIGH | Botslab G980H Dashcams Authentication Bypass by Capture-replay |
| CVE-2026-81630 | 8.1 HIGH | Botslab G980H Dashcams Insufficient Verification of Data Authenticity |
| CVE-2026-88956 | 6.8 MEDIUM | Botslab G980H Dashcams Missing Authentication for Critical Function |
| CVE-2026-79959 | 6.8 MEDIUM | Botslab G980H Dashcams Use of Hard-coded Credentials |
| CVE-2026-82585 | 6.5 MEDIUM | Botslab G980H Dashcams Cleartext Transmission of Sensitive Information |
| CVE-2026-82708 | 6.5 MEDIUM | Botslab G980H Dashcams Improper Limitation of a Pathname to a Restricted Directory |
| CVE-2026-84403 | 6.2 MEDIUM | Botslab G980H Dashcams Missing Authentication for Critical Function |
| CVE-2026-87118 | 5.7 MEDIUM | Botslab G980H Dashcams Out-of-bounds Write |
| CVE-2026-75558 | 5.3 MEDIUM | Botslab G980H Dashcams Use of Hard-coded Cryptographic Key |
| CVE-2026-88761 | 5.3 MEDIUM | Botslab G980H Dashcams Use of Weak Credentials |
No comments yet