Severity: CriticalAction: Review
Vulnerability record
CVE-2026-85496
Severity: HighExploitation: No known exploitation
Patch status
No official fix confirmed yet
Until a fix ships, follow the vendor's mitigations, limit exposure of affected systems, and watch this record for a patch.
Description
The Botslab G980H dash camera firmware generates session identifiers using a small sequential value space rather than a suitably unpredictable source. An unauthenticated attacker with adjacent network access and knowledge that an active session exists could potentially determine a valid session identifier and use it to bypass intended authorization controls.
Source: NIST National Vulnerability Database. Official vulnerability data, reproduced as published.
Intelligence timeline
Developments from the last 30 days, newest first.
- CVSS scoredUpdate
CVE-2026-85496 scored CVSS 7.7
Basis: NIST National Vulnerability Database
