Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.2

CVE-2026-81630: Botslab G980H dash camera can be loaded with malicious firmware

CVE-2026-81630 · published 8 days ago
Summary

The dash camera’s firmware update is downloaded over an unprotected connection and is only checked with a simple integrity value, not a trusted signature. This means an attacker who can intercept the download or submit a crafted update could install altered software and run unauthorized code on the camera. Apply any official firmware updates that include proper signature verification or restrict the device to trusted network environments.

Original advisory text
The Botslab G980H dash camera firmware does not adequately verify the authenticity of firmware updates. The update process retrieves firmware through an unprotected connection and relies on an inte...
The Botslab G980H dash camera firmware does not adequately verify the authenticity of firmware updates. The update process retrieves firmware through an unprotected connection and relies on an integrity value supplied with the firmware instead of a trusted cryptographic signature. A suitably positioned attacker who intercepts a firmware download, or an authenticated attacker who submits a crafted update, could install modified firmware and execute unauthorized code on the device.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
9.2 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-345Insufficient Verification of Data Authenticity
Timeline
Published24 Sep 2026
Updated2 Oct 2026
First seen24 Sep 2026
Sources
Track software like this
Free during beta