CISA Identified Thirteen Vulnerabilities in Botslab Dashcams

The vulnerabilities affect two firmware versions of the Botslab G980H dashcam, exposing users to unauthorized access.

Updated on Sept. 24, 2026 in Cybersecurity

Bold flat-color editorial illustration showing a geometric camera lens above circuitry, representing technical vulnerabilities in consumer hardware.
CISA issued an advisory for thirteen vulnerabilities in Botslab G980H dashcams, warning that attackers could bypass authentication to gain unauthorized device access. AI Illustration. Upload story photo >

Live Poll

Do you trust the security of internet-connected devices in your home or vehicle?

CISA has issued an advisory regarding thirteen vulnerabilities found in the Botslab G980H dashcam, which is manufactured by a China-based company. These flaws, identified in specific firmware versions, could allow attackers to bypass authentication and modify device configurations.

Why it matters

The disclosure highlights critical security risks in consumer hardware that remains connected to networks, potentially granting unauthorized actors access to sensitive user data or system controls. No public exploitation of these specific vulnerabilities has been reported to date.

Thirteen distinct CVEs exist within firmware versions 30010_QHG980HN5294SysFW+ and 58_QHG980HMCN5291SysFW+. These flaws permit unauthorized actors to bypass authentication protocols and gain control over privileged device functionality.

The players

CISA

The Cybersecurity and Infrastructure Security Agency is a United States federal agency responsible for strengthening national security and physical/cyber resilience.

Software Secured

A cybersecurity firm that provides security testing and vulnerability research services.

Julian

A security researcher associated with Software Secured who identified the vulnerabilities.

The details

The vulnerabilities were identified by Julian of Software Secured. Attackers leverage these flaws to bypass security controls, allowing for unauthorized data access and the ability to modify device configurations. These modifications can effectively disrupt the device operation by manipulating its underlying software and privileged logic.

Timeline

  1. September 24, 2026: CISA released the security advisory for the affected Botslab devices.

The Tech Race

This disclosure follows a pattern set by the CISA Known Exploited Vulnerabilities (KEV) Catalog, which documents critical security gaps in active hardware deployments. It highlights the ongoing struggle to secure edge-computing consumer electronics against unauthorized remote access.

Users currently operating the Botslab G980H dashcam should check for manufacturer-provided firmware updates to mitigate unauthorized access risks. While no exploitation has been reported, the presence of these vulnerabilities suggests that the devices should remain isolated from critical networks until patches are applied.

The takeaway

The discovery of thirteen vulnerabilities in a single product line underscores the necessity for regular firmware auditing of connected consumer peripherals. Users should monitor for official patches or manufacturer guidance regarding the G980H firmware versions.

Further reading

For broader trends in device integrity, visit Cybersecurity.

Source note: This article includes information reported by Cisa.

Live Poll

Do you trust the security of internet-connected devices in your home or vehicle?

CISA Identified Thirteen Vulnerabilities in Botslab Dashcams