---
cve: "CVE-2026-79959"
severity: "HIGH"
cvss: 7.0
epss: "0.2%"
vendor: "Botslab"
kev: false
exploited: false
published: "2026-09-24 21:18:44"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-10-01T07:36:57+02:00"
---

# CVE-2026-79959

> 7.0 HIGH · 🧪 PoC

## Beschreibung

The Botslab G980H dash camera firmware contains a hard-coded root account password that cannot be changed by the user. An attacker who obtains the firmware or has physical access to the device could recover the credential and use it to obtain root access through the UART interface.

## CISA-Anreicherung (vulnrichment/ADP)

- CISA-SSVC (Coordinator, v2.0.3):
  - Exploitation: **none**
  - Automatable: **no**
  - Technical Impact: **total**

## CVSS-Vektor

```
CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Physisch | good |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |

## Referenzen

- <https://www.botslab.com/pages/about-botslab>
- <https://www.cisa.gov/news-events/ics-advisories/icsa-26-267-01>
- <https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-267-01.json>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-79959) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI WID (CSAF)_
