CVE-2026-82566

HIGH Status: Deferred

CVSS Scores

CVSS v3.x Base Score
8.8
HIGH

Description

The Botslab G980H dash camera firmware contains a session management vulnerability in which authentication state can remain valid after the associated client connection has been terminated or replaced. Under certain connection conditions, a newly established connection can displace an existing client while previously established session state remains active until a separate expiration mechanism invalidates it. An unauthenticated attacker with adjacent network access could potentially take advantage of this residual authentication state to access functionality associated with another client's session.

Published
September 24, 2026 8:17 PM
Last Modified
September 24, 2026 9:25 PM
Source
[email protected]

Weaknesses (CWE)

CWE-613

References

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.