CVE-2026-82566

The Botslab G980H dash camera firmware contains a session management vulnerability in which authentication state can remain valid after the associated client connection has been terminated or replaced. Under certain connection conditions, a newly established connection can displace an existing client while previously established session state remains active until a separate expiration mechanism invalidates it. An unauthenticated attacker with adjacent network access could potentially take advantage of this residual authentication state to access functionality associated with another client's session.

  • Published Sep 24, 2026
  • CVSS 8.7 high
  • 0.3% chance of exploitation in the next 30 days (EPSS)

Affected software

In the news

CVE-2026-82566 at the National Vulnerability Database