IM
IronMonkey Threat Research
‹ Back to ICS Advisories

Viidure Dashcam Android Application

CRITICAL
CVSS 10.0
Date 2026-09-29T06:00:00+00:00
Source cisa-csaf
Published by CISA

// Description

Successful exploitation of these vulnerabilities could allow attackers to access, modify, or delete sensitive user data and critical system files, potentially compromising the operation of the entire platform.

// Vulnerabilities (2)

CVE ID CVSS Score Severity Description
CVE-2026-96587 10.0 critical
The Viidure Android application embeds permanent, plaintext cloud storage credentials within its compiled code. These credentials provide full access to critical platform storage, including the ability to read, modify, or delete operational files such as firmware and application binaries.
CVE-2026-94204 7.5 high
The central cloud storage backend for the entire dashcam platform is misconfigured with public‑read permissions, allowing unrestricted access to all stored objects. Because this bucket serves as shared storage for the platform, sensitive user records, live dashcam footage, application packages, and firmware files are exposed to anyone on the internet.

// References