L/BLAB BOTSPUBLIC THREAT INTELLIGENCE NODE
CVE KNOWLEDGE BASE

Intelligence
Explorer.

Investigue vulnerabilidades por identificador, produto afetado ou descrição. Use severidade, CVSS e EPSS juntos para orientar a prioridade.

// THREAT ACTIVITY

Grupos & malware emergente

Atividade pública observada em leak sites e repositórios comunitários. Alegações de vítimas não representam confirmação independente de incidente.

RANSOMWARE GROUPSRECENT CLAIMS
qilin12 menções
safepay10 menções
UmBra9 menções
SilentRansomGroup8 menções
Eclipse6 menções
everest5 menções
incransom5 menções
lamashtu4 menções
BYOD3 menções
N0n3 menções
INFOSTEALERSOBSERVED

Sem famílias correlacionadas no recorte recente.

RECENT RANSOMWARE CLAIMSRANSOMWARE.LIVE
BarracudaMinistarstvo poljoprivrede, šumarstva i ribarstvaHR · Agriculture and Food Production · 2026-10-09
nightspirePMG Project Management GroupAE · Professional Services · 2026-10-09
SilentRansomGroupO'Hagan Meyer— · Professional Services · 2026-10-08
netrunnerMid Atlantic Gynecologic Oncology and Pelvic Surgery AssociatesUS · Healthcare · 2026-10-08
UmBraSOCOCOFR · Technology · 2026-10-08
qilinMCM TelecomMX · Technology · 2026-10-08
SilentRansomGroupBaker McKenzieUS · Professional Services · 2026-10-08
UmBraManipal Academy of Higher EduIN · Education · 2026-10-08
UmBraIIT RoorkeeIN · Education · 2026-10-08
UmBraFSE, Cairo UniversityEG · Education · 2026-10-08
payloadBoullard MusiqueFR · Retail & E-Commerce · 2026-10-08
SilentRansomGroupAndersen Group Inc.— · Professional Services · 2026-10-08
MALWARE FAMILIES / 7 DAYSMALWAREBAZAAR
Configure a Auth-Key gratuita do abuse.ch para habilitar detecções recentes do MalwareBazaar.

FONTES: RANSOMWARE.LIVE + MALWAREBAZAAR / ABUSE.CH · CACHE 1H

14535 REGISTROS ENCONTRADOSFEED 2026-10-06
CVE-2026-87118MEDIUM

The Botslab G980H dash camera firmware contains an out of bounds write vulnerability in its command processing functionality. An authenticated attacker with adjacent network access could submit crafted command data that corrupts memory, potentially disrupting authentication state or causing the affected process to terminate and the device to restart, resulting in a temporary denial of service.

AFFECTED SURFACEProduct not specified
CVSS 6.9EPSS 0.24%
CVE-2026-84403MEDIUM

The Botslab G980H dash camera firmware does not require authenticated pairing or client binding before permitting access to Bluetooth Low Energy communications and GATT characteristics. An unauthenticated attacker within Bluetooth range could intercept or directly retrieve sensitive device information, including device identifiers, firmware information, and protected WiFi credentials.

AFFECTED SURFACEProduct not specified
CVSS 6.9EPSS 0.12%
CVE-2026-82716MEDIUM

The Botslab G980H dash camera firmware includes sensitive configuration information, including WiFi credentials, in diagnostic logs generated during the support process. These logs remain accessible on removable storage after the support operation has completed. An unauthenticated attacker with physical access to the storage media could retrieve the logs and obtain sensitive device information.

AFFECTED SURFACEProduct not specified
CVSS 5.1EPSS 0.17%
CVE-2026-82708HIGH

The Botslab G980H dash camera firmware contains a path traversal vulnerability in its HTTP server. An attacker with access to the device's WiFi network could submit a crafted request to access files within the device's removable storage that were not intended to be directly accessible through the web server. Exposed files could include recordings, images, diagnostic logs, or firmware files.

AFFECTED SURFACEProduct not specified
CVSS 7.1EPSS 0.21%
CVE-2026-82585HIGH

The Botslab G980H dash camera firmware transmits sensitive information over unencrypted HTTP and RTSP connections. An attacker capable of intercepting communications on the device's WiFi network could obtain stored recordings, live video, location information, images, diagnostic logs, or other sensitive information exchanged between the device and its mobile application.

AFFECTED SURFACEProduct not specified
CVSS 7.1EPSS 0.12%
CVE-2026-81630CRITICAL

The Botslab G980H dash camera firmware does not adequately verify the authenticity of firmware updates. The update process retrieves firmware through an unprotected connection and relies on an integrity value supplied with the firmware instead of a trusted cryptographic signature. A suitably positioned attacker who intercepts a firmware download, or an authenticated attacker who submits a crafted update, could install modified firmware and execute unauthorized code on the device.

AFFECTED SURFACEProduct not specified
CVSS 9.2EPSS 0.19%
CVE-2026-79959HIGH

The Botslab G980H dash camera firmware contains a hard-coded root account password that cannot be changed by the user. An attacker who obtains the firmware or has physical access to the device could recover the credential and use it to obtain root access through the UART interface.

AFFECTED SURFACEProduct not specified
CVSS 7.0EPSS 0.17%
CVE-2026-75558MEDIUM

The Botslab G980H dash camera firmware uses a hard-coded cryptographic key and initialization vector to protect WiFi credentials communicated by the device. An attacker who obtains the protected credential and extracts the cryptographic material from the firmware could recover the WiFi password and gain unauthorized access to the device network.

AFFECTED SURFACEProduct not specified
CVSS 6.0EPSS 0.16%
CVE-2026-14443HIGH

Incomplete log sanitization during bulk IPsec policy collection in Brocade SANnav versions before 3.0.1a permit extension switch pre-shared keys to be written to system logs. Individuals with read access to container logs or support archives can obtain these keys, leading to the potential compromise of encrypted network tunnels.

AFFECTED SURFACEProduct not specified
CVSS 8.4EPSS 0.11%
CVE-2026-14442MEDIUM

An information exposure vulnerability in the job scheduling component of SANnav allows sensitive credentials to be written to application logs in plain text. When scheduled support save jobs or related operational tasks are executed, sensitive parameters including external server passwords and archive protection keys are logged without proper masking. A local or authenticated user with access to application logs or support bundles can view these cleartext credentials, potentially leading to unauthorized access to remote backup targets or protected archives.

AFFECTED SURFACEProduct not specified
CVSS 6.9EPSS 0.16%
CVE-2026-14441MEDIUM

A logic flaw in Java cache key handling object comparison handling could lead to improper identifier resolution when processing specific user account structures. The issue has been remediated by updating the internal comparison routines to ensure accurate object evaluation and prevent potential identity mismatch conditions.

AFFECTED SURFACEProduct not specified
CVSS 6.9EPSS 0.36%
CVE-2026-97365LOW

A vulnerability was determined in chonkie-inc littrs 0.6.1/0.6.2. Impacted is the function Sandbox::mount of the file crates/littrs/src/lib.rs. Executing a manipulation of the argument relative can lead to path traversal. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

AFFECTED SURFACEProduct not specified
CVSS 2.1EPSS 0.35%
CVE-2026-97326MEDIUM

A weakness has been identified in songxinjianqwe Chat up to ac63d25297079eed5e4ba7e88d3b7a032637150d. Affected by this issue is some unknown functionality of the file chat-server/src/main/java/cn/sinjinsong/chat/server/ChatServer.java of the component chat-server. This manipulation causes server-side request forgery. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The vendor was contacted early about this disclosure but did not respond in any way.

AFFECTED SURFACEProduct not specified
CVSS 5.5EPSS 0.28%
CVE-2026-97325LOW

A security flaw has been discovered in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. Affected by this vulnerability is the function validOAuthClientFromCache of the file yudao-module-system/src/main/java/cn/iocoder/yudao/module/system/service/oauth2/OAuth2ClientServiceImpl.java of the component OAuth2 Client. The manipulation of the argument redirect_uri results in open redirect. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

AFFECTED SURFACEProduct not specified
CVSS 2.1EPSS 0.26%
CVE-2026-97324MEDIUM

A vulnerability was identified in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. Affected is the function updateDemoOrderPaid of the file yudao-module-pay/src/main/java/cn/iocoder/yudao/module/pay/controller/admin/demo/PayDemoOrderController.java of the component Demo-order Payment Callback Handler. The manipulation of the argument ID leads to improper authorization. The attack can be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

AFFECTED SURFACEProduct not specified
CVSS 5.5EPSS 0.28%
CVE-2026-96883HIGH

pgcollection is an open source extension to PostgreSQL. A type confusion issue in AWS pgcollection 2.0.0 through 2.1.1 might allow an authenticated remote user to execute arbitrary code as the postgres operating system user via crafted SQL statements that rely on mismatched type metadata in collection value retrieval and array conversion functions. To remediate this issue, users should upgrade to version 2.1.2 or later.

AFFECTED SURFACEProduct not specified
CVSS 8.7EPSS 0.65%
CVE-2026-93354HIGH

Taskview Community before 1.56.0 contains a missing authentication vulnerability that allows unauthenticated attackers to register arbitrary OAuth clients and take over user accounts by exploiting the OAuth 2.0 Dynamic Client Registration endpoint, which is enabled by default and requires no authentication. Attackers can send a POST request to the registration endpoint to obtain a client_id and client_secret, then craft a malicious authorization link pointing to an attacker-controlled redirect URI to capture authorization codes and exchange them for access tokens granting full API access to victim account data.

AFFECTED SURFACEProduct not specified
CVSS 8.5EPSS 0.27%
CVE-2026-93291CRITICAL

Omni C20 lacks proper certificate validation which could allow an attacker to perform a man-in-the-middle attack which could allow them to execute arbitrary code.

AFFECTED SURFACEProduct not specified
CVSS 9.3EPSS 0.24%
CVE-2026-93290MEDIUM

Omni C20 uses hard-coded credentials that could allow an attacker to monitor log files to obtain credentials to access information like mapping data.

AFFECTED SURFACEProduct not specified
CVSS 6.8EPSS 0.11%
CVE-2026-93289CRITICAL

The affected products are vulnerable to command injection attack that could allow an unauthenticated attacker to execute system commands during the pairing process.

AFFECTED SURFACEProduct not specified
CVSS 9.0EPSS 0.68%
CVE-2026-88956HIGH

The Botslab G980H dash camera firmware contains an authentication vulnerability in the root account exposed through the device's UART interface. The affected account does not require a password before granting access to a privileged system interface, and the interface also displays the device's WiFi password during startup. An unauthenticated attacker with physical access to the device could connect to the UART interface, obtain root privileges, and recover the WiFi password.

AFFECTED SURFACEProduct not specified
CVSS 7.0EPSS 0.22%
CVE-2026-88761MEDIUM

The Botslab G980H dash camera firmware generates the default WiFi password using predictable device information, portions of which are advertised by the product. An unauthenticated attacker within WiFi range could potentially determine the remaining password characters through limited guessing and gain unauthorized access to the device network.

AFFECTED SURFACEProduct not specified
CVSS 6.0EPSS 0.17%
CVE-2026-85496HIGH

The Botslab G980H dash camera firmware generates session identifiers using a small sequential value space rather than a suitably unpredictable source. An unauthenticated attacker with adjacent network access and knowledge that an active session exists could potentially determine a valid session identifier and use it to bypass intended authorization controls.

AFFECTED SURFACEProduct not specified
CVSS 7.7EPSS 0.25%
CVE-2026-84399HIGH

The Botslab G980H dash camera firmware contains an authorization vulnerability in its session based command functionality. The product does not sufficiently associate an authenticated session with the client connection that established it, and subsequent privileged operations rely on possession of a valid session identifier without adequately validating the requesting client's authenticated context. An unauthenticated attacker with adjacent network access could potentially use valid session state associated with another client to access privileged functionality.

AFFECTED SURFACEProduct not specified
CVSS 8.7EPSS 0.19%