Viidure’s Shared Storage Breaks the Trust Boundary
CISA says Viidure Dashcam Android Application version 3.3.1.260403 and earlier is affected by two flaws, CVE-2026-94204 and CVE-2026-96587. The advisory says the platform’s cloud storage is publicly readable, and Viidure’s Android app also embeds permanent cloud credentials, with no fix planned.
Taken together, those two paths let an outsider reach the same shared storage the platform itself uses. CISA says that storage holds user records, live footage, app packages, and firmware, and the embedded credentials can be used to read, modify, or delete operational files such as firmware and application binaries. In plain terms, this is not just exposed data; it is access to the platform’s working parts.
For fleet operators, the exposure sits at the shared storage layer, so a compromise there can affect every device and service that depends on it, not just one user account. If Viidure’s central bucket is part of your operational chain, the blast radius includes whatever that storage can overwrite or remove.
CVSS 7.5 HIGH: the central cloud storage backend for the entire dashcam platform is misconfigured with public-read permissions, allowing unrestricted access to all stored objects.
Viidure Dashcam Android Application Summary Successful exploitation of these vulnerabilities could allow attackers to access, modify, or delete sensitive user data and critical system files, potentially compromising the operation of the entire platform.