CVE-2026-81630

Severity CVSS v4.0:
CRITICAL
Type:
CWE-345 Insufficient Verification of Data Authenticity
Publication date:
24/09/2026
Last modified:
25/09/2026

Description

The Botslab G980H dash camera firmware does not adequately verify the authenticity of firmware updates. The update process retrieves firmware through an unprotected connection and relies on an integrity value supplied with the firmware instead of a trusted cryptographic signature. A suitably positioned attacker who intercepts a firmware download, or an authenticated attacker who submits a crafted update, could install modified firmware and execute unauthorized code on the device.