Viidure Dashcam App Flaws Leave Cloud Footage and Firmware Exposed
CISA warns two flaws in Viidure Dashcam Android app expose user data, live footage and firmware via public cloud storage with no patch available.
Illustrative image generated with AI
CISA warns of two cloud-storage security failures
Two vulnerabilities in the Viidure Dashcam Android Application could expose user records and live footage while also allowing attackers to alter or delete critical platform files.
CISA published ICS Advisory ICSA-26-272-07 on September 29, 2026. The agency identifies Viidure Dashcam Android Application versions 3.3.1.260403 and earlier as affected.
For one vulnerability, the CVE Program defines the affected range more explicitly as versions 0 through 3.3.1.260403. No newer, corrected release has been identified.
Viidure is headquartered in China, while the affected application is deployed worldwide. CISA places the product in the Transportation Systems sector, although the exposed information belongs directly to dashcam users as well as the platform operator.
The two flaws are distinct but potentially compounding. One permits unrestricted reading from shared cloud storage. The other exposes permanent credentials that provide much broader control over that storage.
CISA credits security researcher Bugrahan Karahan with reporting both vulnerabilities.
Public cloud access exposes user data and live footage
The first issue, CVE-2026-94204, is classified as Incorrect Permission Assignment for a Critical Resource, tracked under CWE-732.
The dashcam platform’s shared cloud-storage backend allows public reads. Consequently, objects placed in that environment can be accessed over the internet without the restrictions expected for sensitive data.
The exposed material includes:
- Sensitive user records
- Live dashcam footage
- Android application packages
- Firmware files
This is primarily a confidentiality failure. An attacker does not need an account, existing privileges, or interaction from a victim to read accessible objects.
CVE-2026-94204 has a CVSS 3.1 score of 7.5, rated High:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Its CVSS 4.0 score is 8.7, also rated High:
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Both vectors describe a network-reachable weakness with low attack complexity, no required privileges, and no user interaction. The direct impact measured for this vulnerability is high confidentiality loss, without a corresponding integrity or availability impact.
The CVE Program record confirms the product, affected range, weakness classification, scores, and vectors. It lists publication and an update on September 29, 2026.
Embedded credentials permit modification and deletion
The second vulnerability, CVE-2026-96587, is more severe. It is categorized as Use of Hard-coded Credentials, or CWE-798.
Viidure’s compiled Android application contains permanent cloud-storage credentials in plaintext. Because the secret is embedded in distributed client software rather than protected on a trusted server, it cannot be treated as confidential access material.
CISA says the credentials provide full access to critical platform storage. That access includes the ability to read, modify, or delete operational files, including firmware and application binaries.
CVE-2026-96587 receives the maximum CVSS 3.1 score of 10, rated Critical:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Its CVSS 4.0 score is also 10:
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Unlike the public-read issue, this flaw threatens all three principal security properties. Unauthorized parties could access confidential information, change trusted files, or remove content required for platform operations.
The risk extends beyond individual footage exposure. Tampering with application packages or firmware could affect the integrity of software distributed through the platform, while deleting operational files could impair service availability. CISA warns that successful exploitation may disrupt the operation of the platform as a whole.
The advisory does not describe a required authentication step, local foothold, or victim action. Both CVSS versions characterize exploitation as remotely reachable, low complexity, and possible without privileges or user interaction.
No patch, workaround, or indicators are available
CISA lists no planned fix for either vulnerability. Viidure did not respond to the agency’s coordination attempts, and no technical workaround has been identified.
Affected users are directed to contact Viidure customer support through https://viidure.app/ for further information. However, there is no disclosed patched version to install and no documented configuration change that closes the two cloud-storage failures.
CISA reported no known public exploitation specifically targeting these vulnerabilities when it published the advisory. No indicators of compromise, such as malicious domains, file hashes, account identifiers, or access patterns, have been released.
No inclusion in CISA’s Known Exploited Vulnerabilities catalog or associated federal remediation deadline is identified in the available information. Organizations therefore lack evidence of confirmed exploitation, but they also lack a vendor-provided repair.
That combination complicates response. The absence of public exploitation reports does not establish that exposed objects were never accessed, particularly when one flaw permits anonymous reads and no detection indicators are available.
Defensive steps for users and organizations
Organizations should first identify whether they use Viidure Dashcam Android Application 3.3.1.260403 or earlier. They should also determine which devices, user accounts, operational workflows, and stored files depend on the platform.
Where access logs are available, defenders can review them for unexpected reads, modifications, or deletions. No specific malicious pattern has been published, so any investigation must be based on the organization’s normal activity and retention data.
CISA’s general industrial-control guidance recommends reducing the internet exposure of control-system devices and related systems. Remote devices should be placed behind firewalls and isolated from business networks where feasible.
When remote access is required, organizations should use more secure methods such as VPNs, keep VPN software current, and consider the security of every device connecting through that channel. Defensive changes should follow an impact analysis and risk assessment, particularly where transportation operations may be affected.
These network measures can limit exposure within an organization, but they do not correct public permissions or remove credentials embedded in the Android application. Decisions about continued use should account for the absence of both a patch and a workaround.
CISA additionally recommends defense-in-depth practices and the intrusion-detection approaches described in Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies and ICS-TIP-12-146-01B, Targeted Cyber Intrusion Detection and Mitigation Strategies.
Organizations that observe suspected malicious activity should follow their internal incident-response procedures, preserve relevant evidence, and report findings to CISA for correlation. Users should also avoid links and attachments in unsolicited messages, especially if attackers attempt to exploit concern about the advisory through phishing or fraudulent update notices.
Sources
This article is an original reworking based on the sources below.
- primary sourceCVE Program
- CISA Advisories
CVEs covered in this article
- CVE-2026-96587Critical10.0The Viidure Android application embeds permanent, plaintext cloud storage credentials within its compiled code. These credentials provide full access to critical platform storage, including the ability to read, modify, or delete operational files such as firmware and application binaries.
- CVE-2026-94204High7.5The central cloud storage backend for the entire dashcam platform is misconfigured with public-read permissions, allowing unrestricted access to all stored objects. Because this bucket serves as shared storage for the platform, sensitive user records, live dashcam footage, application packages, and




