Skip to content
Security & Trust

CISA: Botslab has not responded to mitigation requests on G980H dashcam flaws

CISA's advisory lists no vendor fix, so the risk decision sits with whoever bought the camera.

W
WebPulse Newsroom
AI-assisted · 3 min read
Share on X LinkedIn
CISA: Botslab has not responded to mitigation requests on G980H dashcam flaws

AI-generated image for WebPulse. About our images

Key finding

CVE IDs listed per firmware series: 13 (Source: CISA ICS Advisory ICSA-26-267-01 (September 24, 2026))

CISA published advisory ICSA-26-267-01 on September 24, 2026, covering firmware flaws in Botslab G980H dash cameras. In the mitigation entry for each vulnerability, CISA records the same status: the vendor has not replied when asked to collaborate on a fix. CISA lists Transportation Systems as the sector and credits Julian of Software Secured with the report. It also says no known public exploitation targeting these vulnerabilities has been reported to it. For an organisation with these cameras in vehicles, that leaves no vendor fix to schedule, only a decision about the devices.

13
CVE IDs listed per firmware series
Source: CISA ICS Advisory ICSA-26-267-01 (September 24, 2026)
2
Firmware series named as affected
Source: CISA ICS Advisory ICSA-26-267-01 (September 24, 2026)

The WiFi password is the perimeter, and the advisory shows five ways it leaks

CISA describes five separate weaknesses around the device's WiFi credential. The default password is derived from predictable device information, part of which the product advertises. The root interface on the UART port displays the password at startup. Support-process diagnostic logs containing WiFi credentials stay on removable storage. Bluetooth Low Energy access requires no authenticated pairing, and CISA says an attacker in range could retrieve protected WiFi credentials. The fifth sits in the protection around the credential itself: the secrets used to encrypt it are embedded in the firmware, so CISA says an attacker who extracts them and obtains the protected credential could recover the password.

The WiFi credential is not the whole picture. The advisory also lists session-handling and authorization flaws that an unauthenticated attacker with adjacent network access could exploit, plus an out-of-bounds write in command processing that an authenticated adjacent attacker could use to crash the device.

The advisory does not say these were chained in an attack, and it names no exploitation. But the weaknesses are the ones that would matter once a credential is obtained. CISA says the device sends sensitive information over unencrypted HTTP and RTSP, which could expose stored recordings, live video and location information to someone intercepting the WiFi network. A path traversal flaw in the HTTP server could expose files on removable storage, including recordings, diagnostic logs and firmware files.

Firmware and root access have no user-side fix

Two further findings limit what an owner can do. CISA says the root account password is hard-coded and cannot be changed by the user. The update process is a second gap: according to CISA, the camera fetches new firmware over an unprotected connection and checks it against a value bundled with the file, in place of verifying a signature from a trusted party. An attacker positioned to intercept a download, or an authenticated attacker submitting a crafted update, could install modified firmware, according to the advisory.

The two firmware series carry nearly identical CVE lists. CVE-2026-79959 appears only under series 30010_QHG980HN5294SysFW+, and CVE-2026-88956 appears only under series 58_QHG980HMCN5291SysFW+.

With no vendor mitigation, the risk decision moves to the buyer

CISA's only vendor-specific guidance is that users may contact Botslab. Its general recommendations are to minimise network exposure and isolate devices behind firewalls, and they are framed around control systems. In our reading, they fit poorly with a dash camera whose weaknesses include physical access and Bluetooth range. CISA also reminds organisations to run an impact analysis before deploying defensive measures.

The exposure conditions vary by flaw: adjacent network, WiFi range, Bluetooth range, physical access. That makes this a question about where the vehicles are parked and who handles the storage cards, as much as about IT.

Questions to put to your team

1. Do any G980H units run in company vehicles or on employee-owned vehicles used for work, and which of the two firmware series is each on? 2. What recordings and location data sit on those cameras and their removable storage, and who handles the cards after a support call? 3. Does the camera's WiFi network touch any phone or laptop that also reaches corporate systems? 4. Who signs off on the residual risk of keeping a device whose vendor has not responded to CISA's mitigation requests, and on what date is that decision reviewed? 5. Do our contracts for other in-vehicle devices name a security contact and a patch commitment, so we are not in this position again?

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: CISA.

CVEs in this analysis
CVE-2026-88956 CVE-2026-79959
Share this insight