Botslab G980H Dashcams

Summary

CISA has alerted users to multiple vulnerabilities affecting Botslab G980H Dashcams, including authorization bypass, session expiration flaws, and use of weak credentials. Successful exploitation could allow attackers to gain unauthorized access, modify device configurations, and disrupt operations.

IFF Assessment

FOE

The identified vulnerabilities allow for authentication bypass, unauthorized access to sensitive data, and disruption of device operation, posing a significant risk to defenders.

Severity

8.8 High

The CVSS score of 8.8 reflects the critical nature of these vulnerabilities, which allow attackers to bypass authentication and gain privileged access to sensitive data and device functionality, impacting confidentiality, integrity, and availability.

Defender Context

Defenders should be aware of these vulnerabilities in Botslab G980H dashcams, especially in transportation infrastructure where they might be deployed. The combination of authentication bypass and unauthorized access issues highlights the need for rigorous security assessments of IoT devices, particularly those with critical functions.

Read Full Story →