CVE-2026-84403

Severity CVSS v4.0:
MEDIUM
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
24/09/2026
Last modified:
25/09/2026

Description

The Botslab G980H dash camera firmware does not require authenticated pairing or client binding before permitting access to Bluetooth Low Energy communications and GATT characteristics. An unauthenticated attacker within Bluetooth range could intercept or directly retrieve sensitive device information, including device identifiers, firmware information, and protected WiFi credentials.