CVE-2026-96587

Critique10.0Publiée le 29 septembre 2026

The Viidure Android application embeds permanent, plaintext cloud storage credentials within its compiled code. These credentials provide full access to critical platform storage, including the ability to read, modify, or delete operational files such as firmware and application binaries.

Score CVSS10.0 / 10CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Type de faiblesse (CWE)CWE-798

Articles liés

This product uses the NVD API but is not endorsed or certified by the NVD.

Base de données CVE