OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-84399

HIGH · CVSS 8.8 EPSS 0.19% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-24 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

The Botslab G980H dash camera firmware has an authorization vulnerability that allows an unauthenticated attacker with adjacent network access to exploit valid session identifiers, potentially gaining access to privileged operations. This flaw arises from the firmware's failure to properly validate the authenticated context of the requesting client against the established session. Organizations using this dash camera should prioritize remediation to mitigate the risk of unauthorized access to sensitive functionalities.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-84399
Severity
HIGH
CVSS
8.8
EPSS
0.19%

Original NVD Description

The Botslab G980H dash camera firmware contains an authorization vulnerability in its session based command functionality. The product does not sufficiently associate an authenticated session with the client connection that established it, and subsequent privileged operations rely on possession of a valid session identifier without adequately validating the requesting client's authenticated context. An unauthenticated attacker with adjacent network access could potentially use valid session state associated with another client to access privileged functionality.