Thailand connected devices IoT security regulation

Thailand's Dashcam Bulletin Shows the Limits of Advisory-Only IoT Security: Guidelines Without a Duty to Patch

Thailand's NCSA relayed a CISA warning on the Botslab G980H dashcam. Singapore and the UK have already made baseline IoT security a legal duty.

Botslab G980H and Neighbouring IoT Rules People of Internet Research · Thailand 13 CVEs in CISA advisory Affect the first of two G980H firm… 9.2 Firmware flaw CVSS v4.0 Rated Critical; no vendor patch av… 870 CLS-labelled products Singapore Count as of mid-February 2026. peopleofinternet.com
Botslab G980H and Neighbouring IoT Rul… People of Internet Research · Thailand 13 CVEs in CISA advisory 9.2 Firmware flaw CVSS v4.0 870 CLS-labelled products Singapo… peopleofinternet.com

Key Takeaways

On September 25, 2026, Thailand's National Cyber Security Agency (NCSA, via ThaiCERT) circulated a threat bulletin on the Botslab G980H connected dashcam. The bulletin rests on CISA advisory ICSA-26-267-01, released September 24. The episode is a useful test of Thailand's current model for connected-device security, which is advisory and voluntary. It also shows what that model can and cannot deliver.

What the underlying advisory says

The CISA advisory is broader than the NCSA summary suggests. It lists thirteen CVEs across two G980H firmware versions. They include authentication bypass through predictable session IDs and credential replay, unauthenticated UART root access, hard-coded passwords, path traversal in the device's HTTP server, unauthenticated Bluetooth access, and cleartext transmission of recordings and credentials. CVSS v3.1 scores run from 5.3 to 8.8. The firmware-update flaw rates 9.2 (Critical) under CVSS v4.0.

The most important line concerns the vendor: Botslab "has not responded to requests to work with CISA to mitigate this vulnerability." CISA reports no known active exploitation. A public record for the firmware flaw, CVE-2026-81630, lists no available patch. It says the camera fetches updates over an unprotected connection and checks only an integrity value, not a cryptographic signature.

Our reading of the NCSA bulletin, based on the material available to us, is that it lists no CVE numbers and no vendor patch status. A Thai fleet manager or car owner reading it would learn that a problem exists. They would not learn that no fix exists, and that the manufacturer is not engaging.

The case for staying advisory

The strongest argument for Thailand's approach deserves a fair statement. Connected-device markets are global, and Thailand is a small slice of any manufacturer's sales. A mandatory national standard can lock out small importers, fragment the market, and produce paperwork compliance with no gain in security. Voluntary guidance lets a regulator move quickly and avoids freezing a technical standard that will date within a few years. A relay bulletin is also cheap, and it is better than silence.

None of that is wrong. But the dashcam case shows where the argument stops working.

Why guidance alone cannot fix this class of problem

A bulletin informs users, but it cannot compel a non-responsive vendor to ship a patch. By the NCSA's own account, as reported by the Bangkok Post on July 23, 2026, it planned to issue consumer IoT guidelines in September covering no default passwords, firmware updates and vulnerability notifications. We could not retrieve that article independently, and we found no confirmation that the guidelines have been published. Those three topics are exactly where the G980H fails: hard-coded credentials, unsigned firmware, and a vendor that will not take vulnerability reports from CISA.

Even published, voluntary guidelines would depend on the vendor choosing to follow them. The Botslab case is the scenario in which that choice is not made.

What neighbours do differently

Singapore treats these basics as obligations. Under its Cybersecurity Labelling Scheme update announced March 2, 2026, residential routers sold there must already meet Level 1 requirements: unique default passwords, vulnerability management processes and updated software. The Cyber Security Agency is raising the mandatory bar to Level 2, which adds secure communications, encrypted storage of sensitive data and stronger authentication, by the end of 2027. The agency's release cites 2,700 Singapore devices caught in a 2025 global botnet operation and 870 labelled products as of mid-February 2026. Singapore's mandate is narrow, covering routers rather than every gadget, and that narrowness is a feature.

The United Kingdom went further on the same three basics. Its product security regime came into force on April 29, 2024. It bans default passwords on consumer connectable products and requires manufacturers to publish vulnerability-reporting contacts and disclose how long security updates will be supplied.

The lesson from both is not that Thailand needs a sweeping licensing regime. Both target a small set of verifiable, low-cost behaviours: no shared default credentials, a working disclosure channel, and a stated update period. A manufacturer can satisfy each one without redesigning its product or halting innovation.

A proportionate path for Thailand

This publication favours proportionate, evidence-based rules, and that argues for something between a bulletin and a ban. Three steps would fit.

Speed matters here less than sequencing. The risk of waiting is not that Thailand falls behind on a regulatory league table. It is that a vendor with 13 documented vulnerabilities and no response to a foreign government faces no consequence in Thai law. Good regulation of the open internet should reward manufacturers who patch and disclose, and should not leave consumers to guess which ones do.

Bottom line

Thailand's bulletin was a sensible, low-cost act of information sharing. As a regulatory strategy it is incomplete. The dashcam case shows the gap between telling people a device is unsafe and giving anyone a lever to make it safer. A few narrow, well-defined baseline duties would close that gap without a heavy compliance burden, and Singapore and the UK show they can be built.

Sources & Citations

  1. CISA ICSA-26-267-01 Botslab G980H advisory (official CSAF record)
  2. Singapore CSA: Raising cybersecurity labelling requirements for residential routers
  3. OpenCVE: CVE-2026-81630 Botslab G980H
  4. UK PSTI Regulations come into force (Wired-Gov)