vuln-advisoryregulatorNewsThe Broadside1 min read

Viidure Dashcam App Carries One 10.0, One High-Severity Bug

Hardcoded cloud-storage credentials earn CVSS 10; a second, public-read bucket flaw hits 8.7, and the vendor isn't responding.


TL;DR

CISA published ICSA-26-272-07 on two vulnerabilities in the Viidure Dashcam Android Application (versions ≤3.3.1.260403). CVE-2026-96587 embeds plaintext cloud-storage credentials in compiled application code, attackers extracting them gain full read, modify, and delete access to critical platform files including firmware and application binaries (CVSS v4 10). CVE-2026-94204 is a misconfigured cloud storage backend with public-read permissions, exposing user records, live footage, and platform files (CVSS v4 8.7). Viidure did not respond to CISA's coordination attempts. No fix is planned.

Two vulnerabilities in the same Android dashcam application, two very different root causes, and one common outcome: a vendor that didn't answer the phone.

CVE-2026-96587 is the worse of the pair. The Viidure application embeds permanent, plaintext cloud-storage credentials directly in its compiled code, the kind of hardcoded-credential flaw (CWE-798) that gives an attacker full access the moment those strings are extracted. The CVSS v4 vector lands at 10, with both the vulnerable and subsequent system impacted for confidentiality, integrity, and availability. That's not just live footage walking out the door; it's the ability to modify or delete firmware and application binaries on the platform's shared storage.

CVE-2026-94204 is a configuration problem, not a code problem. The cloud storage backend for the entire platform is set to public-read, exposing user records, live dashcam footage, application packages, and firmware to anyone who knows where to look. CISA scores this one at CVSS v4 8.7 (high, not critical) because the impact is read-only. But the exposure radius is the whole platform.

Viidure did not respond to CISA's coordination attempts. The advisory marks remediation status as "No fix planned" and directs users to contact Viidure customer support, a recommendation that reads as procedural boilerplate when the vendor has already declined to engage with the agency whose job is coordinating these disclosures.

The vulnerabilities were reported by a single researcher, Bugrahan Karahan. They affect all versions through 3.3.1.260403. CISA says no known public exploitation targeting these flaws has been reported to the agency.


Published ·Deep Fathom