Vulnerabilities · 16h ago

Viidure’s Shared Storage Breaks the Trust Boundary

CISA says Viidure Dashcam Android Application version 3.3.1.260403 and earlier is affected by two flaws, CVE-2026-94204 and CVE-2026-96587. The advisory says the platform’s cloud storage is publicly readable, and Viidure’s Android app also embeds permanent cloud credentials, with no fix planned.

Taken together, those two paths let an outsider reach the same shared storage the platform itself uses. CISA says that storage holds user records, live footage, app packages, and firmware, and the embedded credentials can be used to read, modify, or delete operational files such as firmware and application binaries. In plain terms, this is not just exposed data; it is access to the platform’s working parts.

For fleet operators, the exposure sits at the shared storage layer, so a compromise there can affect every device and service that depends on it, not just one user account. If Viidure’s central bucket is part of your operational chain, the blast radius includes whatever that storage can overwrite or remove.

CVE-2026-96587

NVD KEV

CVSS 10 CRITICAL: the Viidure Android application embeds permanent, plaintext cloud storage credentials within its compiled code.

CVE-2026-94204

NVD KEV

CVSS 7.5 HIGH: the central cloud storage backend for the entire dashcam platform is misconfigured with public-read permissions, allowing unrestricted access to all stored objects.

Timeline

Sources

1 source covering this story

Entities

Part of the PlainSec briefing for 2026-09-29

Editions

Related stories