On September 25, 2026, Thailand's National Cyber Security Agency (NCSA, via ThaiCERT) circulated a threat bulletin on the Botslab G980H connected dashcam. The bulletin rests on CISA advisory ICSA-26-267-01, released September 24. The episode is a useful test of Thailand's current model for connected-device security, which is advisory and voluntary. It also shows what that model can and cannot deliver.
What the underlying advisory says
The CISA advisory is broader than the NCSA summary suggests. It lists thirteen CVEs across two G980H firmware versions. They include authentication bypass through predictable session IDs and credential replay, unauthenticated UART root access, hard-coded passwords, path traversal in the device's HTTP server, unauthenticated Bluetooth access, and cleartext transmission of recordings and credentials. CVSS v3.1 scores run from 5.3 to 8.8. The firmware-update flaw rates 9.2 (Critical) under CVSS v4.0.
The most important line concerns the vendor: Botslab "has not responded to requests to work with CISA to mitigate this vulnerability." CISA reports no known active exploitation. A public record for the firmware flaw, CVE-2026-81630, lists no available patch. It says the camera fetches updates over an unprotected connection and checks only an integrity value, not a cryptographic signature.
Our reading of the NCSA bulletin, based on the material available to us, is that it lists no CVE numbers and no vendor patch status. A Thai fleet manager or car owner reading it would learn that a problem exists. They would not learn that no fix exists, and that the manufacturer is not engaging.
The case for staying advisory
The strongest argument for Thailand's approach deserves a fair statement. Connected-device markets are global, and Thailand is a small slice of any manufacturer's sales. A mandatory national standard can lock out small importers, fragment the market, and produce paperwork compliance with no gain in security. Voluntary guidance lets a regulator move quickly and avoids freezing a technical standard that will date within a few years. A relay bulletin is also cheap, and it is better than silence.
None of that is wrong. But the dashcam case shows where the argument stops working.
Why guidance alone cannot fix this class of problem
A bulletin informs users, but it cannot compel a non-responsive vendor to ship a patch. By the NCSA's own account, as reported by the Bangkok Post on July 23, 2026, it planned to issue consumer IoT guidelines in September covering no default passwords, firmware updates and vulnerability notifications. We could not retrieve that article independently, and we found no confirmation that the guidelines have been published. Those three topics are exactly where the G980H fails: hard-coded credentials, unsigned firmware, and a vendor that will not take vulnerability reports from CISA.
Even published, voluntary guidelines would depend on the vendor choosing to follow them. The Botslab case is the scenario in which that choice is not made.
What neighbours do differently
Singapore treats these basics as obligations. Under its Cybersecurity Labelling Scheme update announced March 2, 2026, residential routers sold there must already meet Level 1 requirements: unique default passwords, vulnerability management processes and updated software. The Cyber Security Agency is raising the mandatory bar to Level 2, which adds secure communications, encrypted storage of sensitive data and stronger authentication, by the end of 2027. The agency's release cites 2,700 Singapore devices caught in a 2025 global botnet operation and 870 labelled products as of mid-February 2026. Singapore's mandate is narrow, covering routers rather than every gadget, and that narrowness is a feature.
The United Kingdom went further on the same three basics. Its product security regime came into force on April 29, 2024. It bans default passwords on consumer connectable products and requires manufacturers to publish vulnerability-reporting contacts and disclose how long security updates will be supplied.
The lesson from both is not that Thailand needs a sweeping licensing regime. Both target a small set of verifiable, low-cost behaviours: no shared default credentials, a working disclosure channel, and a stated update period. A manufacturer can satisfy each one without redesigning its product or halting innovation.
A proportionate path for Thailand
This publication favours proportionate, evidence-based rules, and that argues for something between a bulletin and a ban. Three steps would fit.
- Finish the guidelines, then attach consequences. Publish the September guidelines and tie them to public-sector and critical-fleet procurement. That uses purchasing power instead of penalties and imposes no cost on compliant firms.
- Make the bulletins more useful. Every advisory should list CVE identifiers, affected versions, and plainly whether a patch exists or the vendor has not responded. Mitigations such as network segmentation and VPN access, which CISA recommends, should be spelled out for consumers.
- Legislate narrowly if voluntary compliance fails. A short list of baseline duties, modelled on Singapore's Level 1 and the UK's three requirements, would be the right trigger point. Set a review date, perhaps twelve months after the guidelines appear, and measure uptake first.
Speed matters here less than sequencing. The risk of waiting is not that Thailand falls behind on a regulatory league table. It is that a vendor with 13 documented vulnerabilities and no response to a foreign government faces no consequence in Thai law. Good regulation of the open internet should reward manufacturers who patch and disclose, and should not leave consumers to guess which ones do.
Bottom line
Thailand's bulletin was a sensible, low-cost act of information sharing. As a regulatory strategy it is incomplete. The dashcam case shows the gap between telling people a device is unsafe and giving anyone a lever to make it safer. A few narrow, well-defined baseline duties would close that gap without a heavy compliance burden, and Singapore and the UK show they can be built.