The Botslab G980H dash camera firmware contains an out of bounds write vulnerability in its command processing functionality. An authenticated attacker with adjacent network access could submit crafted command data that corrupts memory, potentially disrupting authentication state or causing the affected process to terminate and the device to restart, resulting in a temporary denial of service.
Botslab G980H Dashcams Out-of-bounds Write
Problem type
Affected products
Botslab
30010_QHG980HN5294SysFW+ - AFFECTED
58_QHG980HMCN5291SysFW+ - AFFECTED
References
https://www.botslab.com/pages/about-botslab
https://www.cisa.gov/news-events/ics-advisories/icsa-26-267-01
https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-267-01.json
GitHub Security Advisories
GHSA-cf7c-rf68-qh4g
The Botslab G980H dash camera firmware contains an out of bounds write vulnerability in its...
https://github.com/advisories/GHSA-cf7c-rf68-qh4gThe Botslab G980H dash camera firmware contains an out of bounds write vulnerability in its command processing functionality. An authenticated attacker with adjacent network access could submit crafted command data that corrupts memory, potentially disrupting authentication state or causing the affected process to terminate and the device to restart, resulting in a temporary denial of service.
https://nvd.nist.gov/vuln/detail/CVE-2026-87118
https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-267-01.json
https://www.botslab.com/pages/about-botslab
https://www.cisa.gov/news-events/ics-advisories/icsa-26-267-01
https://github.com/advisories/GHSA-cf7c-rf68-qh4g
JSON source
https://cveawg.mitre.org/api/cve/CVE-2026-87118Click to expand
{
"dataType": "CVE_RECORD",
"dataVersion": "5.2",
"cveMetadata": {
"cveId": "CVE-2026-87118",
"assignerOrgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
"assignerShortName": "icscert",
"dateUpdated": "2026-09-24T20:17:49.712Z",
"dateReserved": "2026-09-10T15:25:29.834Z",
"datePublished": "2026-09-24T20:17:49.712Z",
"state": "PUBLISHED"
},
"containers": {
"cna": {
"providerMetadata": {
"orgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
"shortName": "icscert",
"dateUpdated": "2026-09-24T20:17:49.712Z"
},
"datePublic": "2026-09-24T14:31:00.000Z",
"title": "Botslab G980H Dashcams Out-of-bounds Write",
"descriptions": [
{
"lang": "en",
"value": "The Botslab G980H dash camera firmware contains an out of bounds write vulnerability in its command processing functionality. An authenticated attacker with adjacent network access could submit crafted command data that corrupts memory, potentially disrupting authentication state or causing the affected process to terminate and the device to restart, resulting in a temporary denial of service.",
"supportingMedia": [
{
"type": "text/html",
"base64": false,
"value": "The Botslab G980H dash camera firmware contains an out of bounds write vulnerability in its command processing functionality. An authenticated attacker with adjacent network access could submit crafted command data that corrupts memory, potentially disrupting authentication state or causing the affected process to terminate and the device to restart, resulting in a temporary denial of service.<br>"
}
]
}
],
"affected": [
{
"vendor": "Botslab",
"product": "G980H",
"defaultStatus": "unaffected",
"versions": [
{
"version": "30010_QHG980HN5294SysFW+",
"status": "affected"
},
{
"version": "58_QHG980HMCN5291SysFW+",
"status": "affected"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"lang": "en",
"description": "CWE-787 Out-of-bounds write",
"cweId": "CWE-787",
"type": "CWE"
}
]
}
],
"references": [
{
"url": "https://www.botslab.com/pages/about-botslab"
},
{
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-267-01"
},
{
"url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-267-01.json"
}
],
"metrics": [
{
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
],
"cvssV3_1": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"attackVector": "ADJACENT_NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"availabilityImpact": "HIGH",
"baseScore": 5.7,
"baseSeverity": "MEDIUM"
}
}
],
"workarounds": [
{
"lang": "en",
"value": "Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information: https://www.botslab.com/pages/about-botslab",
"supportingMedia": [
{
"type": "text/html",
"base64": false,
"value": "Botslab has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of G980H Dashcams are invited to reach out to Botslab for more information: <a href=\"https://www.botslab.com/pages/about-botslab\">https://www.botslab.com/pages/about-botslab</a>"
}
]
}
],
"credits": [
{
"lang": "en",
"value": "Julian of Software Secured reported this vulnerability to CISA.",
"type": "finder"
}
]
}
}
}