---
cve: "CVE-2026-82708"
severity: "HIGH"
cvss: 7.1
epss: ""
vendor: "Botslab"
kev: false
exploited: false
published: "2026-09-24 21:18:50"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-28T01:44:08+02:00"
---

# CVE-2026-82708

> 7.1 HIGH · 🧪 PoC

## Beschreibung

The Botslab G980H dash camera firmware contains a path traversal vulnerability in its HTTP server. An attacker with access to the device's WiFi network could submit a crafted request to access files within the device's removable storage that were not intended to be directly accessible through the web server. Exposed files could include recordings, images, diagnostic logs, or firmware files.

## CVSS-Vektor

```
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Benachbart | warn |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |

## Referenzen

- <https://www.botslab.com/pages/about-botslab>
- <https://www.cisa.gov/news-events/ics-advisories/icsa-26-267-01>
- <https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-267-01.json>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-82708) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI WID (CSAF)_
