The Botslab G980H dash camera firmware transmits sensitive information over unencrypted HTTP and RTSP connections. An attacker capable of intercepting communications on the device's WiFi network could obtain stored recordings, live video, location information, images, diagnostic logs, or other sensitive information exchanged between the device and its mobile application.
Botslab G980H Dashcams Cleartext Transmission of Sensitive Information
Problem type
Affected products
Botslab
30010_QHG980HN5294SysFW+ - AFFECTED
58_QHG980HMCN5291SysFW+ - AFFECTED
References
https://www.botslab.com/pages/about-botslab
https://www.cisa.gov/news-events/ics-advisories/icsa-26-267-01
https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-267-01.json
GitHub Security Advisories
GHSA-mrfq-pqvw-wjqq
The Botslab G980H dash camera firmware transmits sensitive information over unencrypted HTTP and...
https://github.com/advisories/GHSA-mrfq-pqvw-wjqqThe Botslab G980H dash camera firmware transmits sensitive information over unencrypted HTTP and RTSP connections. An attacker capable of intercepting communications on the device's WiFi network could obtain stored recordings, live video, location information, images, diagnostic logs, or other sensitive information exchanged between the device and its mobile application.
https://nvd.nist.gov/vuln/detail/CVE-2026-82585
https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-267-01.json
https://www.botslab.com/pages/about-botslab
https://www.cisa.gov/news-events/ics-advisories/icsa-26-267-01
https://github.com/advisories/GHSA-mrfq-pqvw-wjqq
JSON source
https://cveawg.mitre.org/api/cve/CVE-2026-82585Click to expand
{
"dataType": "CVE_RECORD",
"dataVersion": "5.2",
"cveMetadata": {
"cveId": "CVE-2026-82585",
"assignerOrgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
"assignerShortName": "icscert",
"dateUpdated": "2026-09-24T20:28:47.491Z",
"dateReserved": "2026-09-10T15:25:29.844Z",
"datePublished": "2026-09-24T20:28:47.491Z",
"state": "PUBLISHED"
},
"containers": {
"cna": {
"providerMetadata": {
"orgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
"shortName": "icscert",
"dateUpdated": "2026-09-24T20:28:47.491Z"
},
"datePublic": "2026-09-24T14:31:00.000Z",
"title": "Botslab G980H Dashcams Cleartext Transmission of Sensitive Information",
"descriptions": [
{
"lang": "en",
"value": "The Botslab G980H dash camera firmware transmits sensitive information over unencrypted HTTP and RTSP connections. An attacker capable of intercepting communications on the device's WiFi network could obtain stored recordings, live video, location information, images, diagnostic logs, or other sensitive information exchanged between the device and its mobile application.",
"supportingMedia": [
{
"type": "text/html",
"base64": false,
"value": "The Botslab G980H dash camera firmware transmits sensitive information over unencrypted HTTP and RTSP connections. An attacker capable of intercepting communications on the device's WiFi network could obtain stored recordings, live video, location information, images, diagnostic logs, or other sensitive information exchanged between the device and its mobile application. <br>"
}
]
}
],
"affected": [
{
"vendor": "Botslab",
"product": "G980H",
"defaultStatus": "unaffected",
"versions": [
{
"version": "30010_QHG980HN5294SysFW+",
"status": "affected"
},
{
"version": "58_QHG980HMCN5291SysFW+",
"status": "affected"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"lang": "en",
"description": "CWE-319 Cleartext transmission of sensitive information",
"cweId": "CWE-319",
"type": "CWE"
}
]
}
],
"references": [
{
"url": "https://www.botslab.com/pages/about-botslab"
},
{
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-267-01"
},
{
"url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-267-01.json"
}
],
"metrics": [
{
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
],
"cvssV3_1": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"attackVector": "ADJACENT_NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"availabilityImpact": "NONE",
"baseScore": 6.5,
"baseSeverity": "MEDIUM"
}
}
],
"workarounds": [
{
"lang": "en",
"value": "Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information: https://www.botslab.com/pages/about-botslab",
"supportingMedia": [
{
"type": "text/html",
"base64": false,
"value": "Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information: <a href=\"https://www.botslab.com/pages/about-botslab\">https://www.botslab.com/pages/about-botslab</a>"
}
]
}
],
"credits": [
{
"lang": "en",
"value": "Julian of Software Secured reported this vulnerability to CISA.",
"type": "finder"
}
]
}
}
}