CVE-2026-96587

Critica10.0Pubblicata il 29 settembre 2026

The Viidure Android application embeds permanent, plaintext cloud storage credentials within its compiled code. These credentials provide full access to critical platform storage, including the ability to read, modify, or delete operational files such as firmware and application binaries.

Punteggio CVSS10.0 / 10CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Tipo di debolezza (CWE)CWE-798

Articoli correlati

This product uses the NVD API but is not endorsed or certified by the NVD.

Database CVE