MinorCritical vulnerability
CVE-2026-85496 (CVSS 7.7)
NVD · officialPublished Sep 24, 2026Risk 23/100
The Botslab G980H dash camera firmware generates session identifiers using a small sequential value space rather than a suitably unpredictable source. An unauthenticated attacker with adjacent network access and knowledge that an active session exists could potentially determine a valid session identifier and use it to bypass intended authorization controls.
Technical details
CVSS
7.7
AV:AdjacentAC:LowPR:NoneUI:None
Evidence and sources
This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source