2026-09-24 20:28CVE-2026-82585icscert
PUBLISHED5.2CWE-319

Botslab G980H Dashcams Cleartext Transmission of Sensitive Information

The Botslab G980H dash camera firmware transmits sensitive information over unencrypted HTTP and RTSP connections. An attacker capable of intercepting communications on the device's WiFi network could obtain stored recordings, live video, location information, images, diagnostic logs, or other sensitive information exchanged between the device and its mobile application.

Problem type

Affected products

Botslab

G980H

30010_QHG980HN5294SysFW+ - AFFECTED

58_QHG980HMCN5291SysFW+ - AFFECTED

References

GitHub Security Advisories

GHSA-mrfq-pqvw-wjqq

The Botslab G980H dash camera firmware transmits sensitive information over unencrypted HTTP and...

https://github.com/advisories/GHSA-mrfq-pqvw-wjqq

The Botslab G980H dash camera firmware transmits sensitive information over unencrypted HTTP and RTSP connections. An attacker capable of intercepting communications on the device's WiFi network could obtain stored recordings, live video, location information, images, diagnostic logs, or other sensitive information exchanged between the device and its mobile application.

JSON source

https://cveawg.mitre.org/api/cve/CVE-2026-82585
Click to expand
{
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "cveMetadata": {
    "cveId": "CVE-2026-82585",
    "assignerOrgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
    "assignerShortName": "icscert",
    "dateUpdated": "2026-09-24T20:28:47.491Z",
    "dateReserved": "2026-09-10T15:25:29.844Z",
    "datePublished": "2026-09-24T20:28:47.491Z",
    "state": "PUBLISHED"
  },
  "containers": {
    "cna": {
      "providerMetadata": {
        "orgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
        "shortName": "icscert",
        "dateUpdated": "2026-09-24T20:28:47.491Z"
      },
      "datePublic": "2026-09-24T14:31:00.000Z",
      "title": "Botslab G980H Dashcams Cleartext Transmission of Sensitive Information",
      "descriptions": [
        {
          "lang": "en",
          "value": "The Botslab G980H dash camera firmware transmits sensitive information over unencrypted HTTP and RTSP connections. An attacker capable of intercepting communications on the device's WiFi network could obtain stored recordings, live video, location information, images, diagnostic logs, or other sensitive information exchanged between the device and its mobile application.",
          "supportingMedia": [
            {
              "type": "text/html",
              "base64": false,
              "value": "The Botslab G980H dash camera firmware transmits sensitive information over unencrypted HTTP and RTSP connections. An attacker capable of intercepting communications on the device's WiFi network could obtain stored recordings, live video, location information, images, diagnostic logs, or other sensitive information exchanged between the device and its mobile application.&nbsp;<br>"
            }
          ]
        }
      ],
      "affected": [
        {
          "vendor": "Botslab",
          "product": "G980H",
          "defaultStatus": "unaffected",
          "versions": [
            {
              "version": "30010_QHG980HN5294SysFW+",
              "status": "affected"
            },
            {
              "version": "58_QHG980HMCN5291SysFW+",
              "status": "affected"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "lang": "en",
              "description": "CWE-319 Cleartext transmission of sensitive information",
              "cweId": "CWE-319",
              "type": "CWE"
            }
          ]
        }
      ],
      "references": [
        {
          "url": "https://www.botslab.com/pages/about-botslab"
        },
        {
          "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-267-01"
        },
        {
          "url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-267-01.json"
        }
      ],
      "metrics": [
        {
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        },
        {
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ],
          "cvssV3_1": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "attackVector": "ADJACENT_NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "scope": "UNCHANGED",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "availabilityImpact": "NONE",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM"
          }
        }
      ],
      "workarounds": [
        {
          "lang": "en",
          "value": "Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information:  https://www.botslab.com/pages/about-botslab",
          "supportingMedia": [
            {
              "type": "text/html",
              "base64": false,
              "value": "Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information: <a href=\"https://www.botslab.com/pages/about-botslab\">https://www.botslab.com/pages/about-botslab</a>"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "value": "Julian of Software Secured reported this vulnerability to CISA.",
          "type": "finder"
        }
      ]
    }
  }
}