Vulnerability record

CVE-2026-84403

Severity: ElevatedExploitation: No known exploitation

Patch status

No official fix confirmed yet

Until a fix ships, follow the vendor's mitigations, limit exposure of affected systems, and watch this record for a patch.

Description

The Botslab G980H dash camera firmware does not require authenticated pairing or client binding before permitting access to Bluetooth Low Energy communications and GATT characteristics. An unauthenticated attacker within Bluetooth range could intercept or directly retrieve sensitive device information, including device identifiers, firmware information, and protected WiFi credentials.

Source: NIST National Vulnerability Database. Official vulnerability data, reproduced as published.

Intelligence timeline

Developments from the last 30 days, newest first.

  1. CVSS scoredUpdate

    CVE-2026-84403 scored CVSS 6.9

    Basis: NIST National Vulnerability Database

Coverage

References

  • github.com https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-267-01.json
  • botslab.com https://www.botslab.com/pages/about-botslab
  • cisa.gov https://www.cisa.gov/news-events/ics-advisories/icsa-26-267-01