The Botslab G980H dash camera firmware contains a hard-coded root account password that cannot be changed by the user. An attacker who obtains the firmware or has physical access to the device could recover the credential and use it to obtain root access through the UART interface.
Botslab G980H Dashcams Use of Hard-coded Credentials
Problem type
Affected products
Botslab
30010_QHG980HN5294SysFW+ - AFFECTED
58_QHG980HMCN5291SysFW+ - AFFECTED
References
https://www.botslab.com/pages/about-botslab
https://www.cisa.gov/news-events/ics-advisories/icsa-26-267-01
https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-267-01.json
GitHub Security Advisories
GHSA-f3h4-c3cq-ch4g
The Botslab G980H dash camera firmware contains a hard-coded root account password that cannot be...
https://github.com/advisories/GHSA-f3h4-c3cq-ch4gThe Botslab G980H dash camera firmware contains a hard-coded root account password that cannot be changed by the user. An attacker who obtains the firmware or has physical access to the device could recover the credential and use it to obtain root access through the UART interface.
https://nvd.nist.gov/vuln/detail/CVE-2026-79959
https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-267-01.json
https://www.botslab.com/pages/about-botslab
https://www.cisa.gov/news-events/ics-advisories/icsa-26-267-01
https://github.com/advisories/GHSA-f3h4-c3cq-ch4g
JSON source
https://cveawg.mitre.org/api/cve/CVE-2026-79959Click to expand
{
"dataType": "CVE_RECORD",
"dataVersion": "5.2",
"cveMetadata": {
"cveId": "CVE-2026-79959",
"assignerOrgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
"assignerShortName": "icscert",
"dateUpdated": "2026-09-24T20:25:02.973Z",
"dateReserved": "2026-09-10T15:25:29.841Z",
"datePublished": "2026-09-24T20:25:02.973Z",
"state": "PUBLISHED"
},
"containers": {
"cna": {
"providerMetadata": {
"orgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
"shortName": "icscert",
"dateUpdated": "2026-09-24T20:25:02.973Z"
},
"datePublic": "2026-09-24T14:31:00.000Z",
"title": "Botslab G980H Dashcams Use of Hard-coded Credentials",
"descriptions": [
{
"lang": "en",
"value": "The Botslab G980H dash camera firmware contains a hard-coded root account password that cannot be changed by the user. An attacker who obtains the firmware or has physical access to the device could recover the credential and use it to obtain root access through the UART interface.",
"supportingMedia": [
{
"type": "text/html",
"base64": false,
"value": "The Botslab G980H dash camera firmware contains a hard-coded root account password that cannot be changed by the user. An attacker who obtains the firmware or has physical access to the device could recover the credential and use it to obtain root access through the UART interface.<br>"
}
]
}
],
"affected": [
{
"vendor": "Botslab",
"product": "G980H",
"defaultStatus": "unaffected",
"versions": [
{
"version": "30010_QHG980HN5294SysFW+",
"status": "affected"
},
{
"version": "58_QHG980HMCN5291SysFW+",
"status": "affected"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"lang": "en",
"description": "CWE-798",
"cweId": "CWE-798",
"type": "CWE"
}
]
}
],
"references": [
{
"url": "https://www.botslab.com/pages/about-botslab"
},
{
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-267-01"
},
{
"url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-267-01.json"
}
],
"metrics": [
{
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
],
"cvssV3_1": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"attackVector": "PHYSICAL",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH",
"baseScore": 6.8,
"baseSeverity": "MEDIUM"
}
}
],
"workarounds": [
{
"lang": "en",
"value": "Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information: https://www.botslab.com/pages/about-botslab",
"supportingMedia": [
{
"type": "text/html",
"base64": false,
"value": "Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information: <a href=\"https://www.botslab.com/pages/about-botslab\">https://www.botslab.com/pages/about-botslab</a>"
}
]
}
],
"credits": [
{
"lang": "en",
"value": "Julian of Software Secured reported this vulnerability to CISA.",
"type": "finder"
}
]
}
}
}