Botslab G980H行车记录仪固件在通过设备UART接口暴露的root账户中存在认证漏洞。受影响账户在授予对特权系统接口的访问权限前无需密码,并且该接口在设备启动时会显示WiFi密码。具备物理访问权限的未授权攻击者可以通过连接UART接口获取root权限,并恢复WiFi密码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82566 | 8.8 HIGH | Botslab G980H Dashcams Insufficient session expiration |
| CVE-2026-85496 | 8.8 HIGH | Botslab G980H Dashcams Generation of Predictable Numbers or Identifiers |
| CVE-2026-84399 | 8.8 HIGH | Botslab G980H Dashcams Incorrect Authorization |
| CVE-2026-77967 | 8.1 HIGH | Botslab G980H Dashcams Authentication Bypass by Capture-replay |
| CVE-2026-81630 | 8.1 HIGH | Botslab G980H Dashcams Insufficient Verification of Data Authenticity |
| CVE-2026-79959 | 6.8 MEDIUM | Botslab G980H Dashcams Use of Hard-coded Credentials |
| CVE-2026-82585 | 6.5 MEDIUM | Botslab G980H Dashcams Cleartext Transmission of Sensitive Information |
| CVE-2026-82708 | 6.5 MEDIUM | Botslab G980H Dashcams Improper Limitation of a Pathname to a Restricted Directory |
| CVE-2026-84403 | 6.2 MEDIUM | Botslab G980H Dashcams Missing Authentication for Critical Function |
| CVE-2026-87118 | 5.7 MEDIUM | Botslab G980H Dashcams Out-of-bounds Write |
| CVE-2026-75558 | 5.3 MEDIUM | Botslab G980H Dashcams Use of Hard-coded Cryptographic Key |
| CVE-2026-88761 | 5.3 MEDIUM | Botslab G980H Dashcams Use of Weak Credentials |
| CVE-2026-82716 | 4.6 MEDIUM | Botslab G980H Dashcams Insertion of Sensitive Information into Log File |
No comments yet