{"id":"CVE-2026-82566","published":"2026-09-24T20:17:32.503","lastModified":"2026-09-24T21:25:27.050","description":"The Botslab G980H dash camera firmware contains a session management vulnerability in which authentication state can remain valid after the associated client connection has been terminated or replaced. Under certain connection conditions, a newly established connection can displace an existing client while previously established session state remains active until a separate expiration mechanism invalidates it. An unauthenticated attacker with adjacent network access could potentially take advantage of this residual authentication state to access functionality associated with another client's session.","cvssScore":8.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-613"],"vendors":[],"products":[],"references":[{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-267-01.json","tags":[]},{"url":"https://www.botslab.com/pages/about-botslab","tags":[]},{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-267-01","tags":[]}],"exploitRefs":[{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-267-01.json","tags":[]}],"hasPoc":true,"ai":{"summary":"The flaw in the Botslab G980H dash camera firmware allows an unauthenticated attacker to exploit residual authentication state, gaining unauthorized access to another client's session.","exploitability":"Exploitation is moderately difficult requiring adjacent network access and specific connection conditions to displace an existing client.","blast_radius":"If exploited, the attacker could gain full access to the displaced client's session, potentially leading to data theft or control of the camera's functionality.","remediation":"Disable the affected feature or upgrade to the latest firmware version as soon as possible.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["auth-bypass","firmware","network"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-29T09:03:09.885Z"}}