2026-09-24 20:21CVE-2026-82708icscert
PUBLISHED5.2CWE-22

Botslab G980H Dashcams Improper Limitation of a Pathname to a Restricted Directory

The Botslab G980H dash camera firmware contains a path traversal vulnerability in its HTTP server. An attacker with access to the device's WiFi network could submit a crafted request to access files within the device's removable storage that were not intended to be directly accessible through the web server. Exposed files could include recordings, images, diagnostic logs, or firmware files.

Problem type

Affected products

Botslab

G980H

30010_QHG980HN5294SysFW+ - AFFECTED

58_QHG980HMCN5291SysFW+ - AFFECTED

References

GitHub Security Advisories

GHSA-9372-p39g-vqhj

The Botslab G980H dash camera firmware contains a path traversal vulnerability in its HTTP server...

https://github.com/advisories/GHSA-9372-p39g-vqhj

The Botslab G980H dash camera firmware contains a path traversal vulnerability in its HTTP server. An attacker with access to the device's WiFi network could submit a crafted request to access files within the device's removable storage that were not intended to be directly accessible through the web server. Exposed files could include recordings, images, diagnostic logs, or firmware files.

JSON source

https://cveawg.mitre.org/api/cve/CVE-2026-82708
Click to expand
{
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "cveMetadata": {
    "cveId": "CVE-2026-82708",
    "assignerOrgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
    "assignerShortName": "icscert",
    "dateUpdated": "2026-09-24T20:21:35.165Z",
    "dateReserved": "2026-09-10T15:25:29.837Z",
    "datePublished": "2026-09-24T20:21:35.165Z",
    "state": "PUBLISHED"
  },
  "containers": {
    "cna": {
      "providerMetadata": {
        "orgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
        "shortName": "icscert",
        "dateUpdated": "2026-09-24T20:21:35.165Z"
      },
      "datePublic": "2026-09-24T14:31:00.000Z",
      "title": "Botslab G980H Dashcams Improper Limitation of a Pathname to a Restricted Directory",
      "descriptions": [
        {
          "lang": "en",
          "value": "The Botslab G980H dash camera firmware contains a path traversal vulnerability in its HTTP server. An attacker with access to the device's WiFi network could submit a crafted request to access files within the device's removable storage that were not intended to be directly accessible through the web server. Exposed files could include recordings, images, diagnostic logs, or firmware files.",
          "supportingMedia": [
            {
              "type": "text/html",
              "base64": false,
              "value": "The Botslab G980H dash camera firmware contains a path traversal vulnerability in its HTTP server. An attacker with access to the device's WiFi network could submit a crafted request to access files within the device's removable storage that were not intended to be directly accessible through the web server. Exposed files could include recordings, images, diagnostic logs, or firmware files.<br>"
            }
          ]
        }
      ],
      "affected": [
        {
          "vendor": "Botslab",
          "product": "G980H",
          "defaultStatus": "unaffected",
          "versions": [
            {
              "version": "30010_QHG980HN5294SysFW+",
              "status": "affected"
            },
            {
              "version": "58_QHG980HMCN5291SysFW+",
              "status": "affected"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "lang": "en",
              "description": "CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
              "cweId": "CWE-22",
              "type": "CWE"
            }
          ]
        }
      ],
      "references": [
        {
          "url": "https://www.botslab.com/pages/about-botslab"
        },
        {
          "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-267-01"
        },
        {
          "url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-267-01.json"
        }
      ],
      "metrics": [
        {
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        },
        {
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ],
          "cvssV3_1": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "attackVector": "ADJACENT_NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "scope": "UNCHANGED",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "availabilityImpact": "NONE",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM"
          }
        }
      ],
      "workarounds": [
        {
          "lang": "en",
          "value": "Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information:  https://www.botslab.com/pages/about-botslab",
          "supportingMedia": [
            {
              "type": "text/html",
              "base64": false,
              "value": "Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information: <a href=\"https://www.botslab.com/pages/about-botslab\">https://www.botslab.com/pages/about-botslab</a>"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "value": "Julian of Software Secured reported this vulnerability to CISA.",
          "type": "finder"
        }
      ]
    }
  }
}