CVE-2026-81630
Last modified
CVE-2026-81630 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. The Botslab G980H dash camera firmware does not adequately verify the authenticity of firmware updates. The update process retrieves firmware through an unprotected connection and relies on an integrity value supplied with the firmware instead of a trusted cryptographic signature.
Description
The Botslab G980H dash camera firmware does not adequately verify the authenticity of firmware updates. The update process retrieves firmware through an unprotected connection and relies on an integrity value supplied with the firmware instead of a trusted cryptographic signature. A suitably positioned attacker who intercepts a firmware download, or an authenticated attacker who submits a crafted update, could install modified firmware and execute unauthorized code on the device.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Botslab | G980H | 30010_QHG980HN5294SysFW+; 58_QHG980HMCN5291SysFW+ |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-81630?
How severe is CVE-2026-81630?
How do I fix CVE-2026-81630?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-81623IBM Guardium Data Protection 12.2 could allow an authenticat…6.3
- CVE-2026-81624Undertow is a flexible performant web server used in JBoss E…7.5
- CVE-2026-81625A remote attacker with user privileges may use a malicious o…8.8
- CVE-2026-81626IBM Guardium Data Protection 12.2 is vulnerable to a SQL inj…8.6
- CVE-2026-81627A flaw was found in QEMU. The VAPIC setup hypercall in hw/i3…8.2
- CVE-2026-8163The Infility Global WordPress plugin before 2.15.19 does not…8.8
- CVE-2026-81632Use of HTTP Request With Sensitive Query String vulnerabilit…7.2
- CVE-2026-81633Improper Input Validation vulnerability in ash-project ash_g…6.9
- CVE-2026-81634In NLnet Labs Unbound up to and including 1.26.0, a 255 leng…7.5
- CVE-2026-81635A cross-site scripting vulnerability exists in SHIRASAGI, wh…5.1
- CVE-2026-81636Allocation of Resources Without Limits or Throttling vulnera…8.7
- CVE-2026-81637Insufficient Session Expiration vulnerability in team-alembi…2.3
Are you affected by CVE-2026-81630?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
