important · Firmware — Bluetooth
Botslab’s BLE, session and update flaws form a provisional path to modified G980H firmware.
Affects
Botslab G980H dash cameras, embedded recording devices with BLE provisioning, a local Wi-Fi network, HTTP services, and network-delivered firmware updates.
Unauthenticated BLE exposes protected Wi-Fi material; firmware-wide constants can recover it; session weaknesses expose privileged functions; and the updater lacks trusted-signature verification.
Detail and 4 sources
The complete chain has not been demonstrated on stock hardware, and we do not know the upload authorization route or final execution identity.
Sources
Researchhttps://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-267-01.jsonCode / PoCCSAF/csaf_files/OT/white/2026/icsa-26-267-01.json at develop · cisagov/CSAF · GitHubSecondaryBotslab G980H exposes Wi-Fi credentials through unauthenticated BLE pairingSecondaryBotslab G980H path traversal exposes recordings and firmware files