TL;DR
CISA published advisory ICSA-26-272-07 on September 29, 2026, covering two flaws in the Viidure dashcam app for Android. The worst, CVE-2026-96587, scores a maximum CVSS 10.0 for hardcoded cloud credentials. Viidure did not respond to CISA, and no fix is available.
- Product: Viidure Dashcam Android Application
- Vulnerabilities: 2 flaws (CVE-2026-96587, CVE-2026-94204)
- Highest severity: 10.0 (Critical · CVSSv4)
- Worst impact: Use of Hard-coded Credentials in
- Status: No confirmed exploitation yet
- Action: See vendor advisories
| CVE | CVSS (CVSSv4) | Type | Status |
|---|---|---|---|
| CVE-2026-96587 | 10 | Use of Hard-coded Credentials in | Not exploited |
| CVE-2026-94204 | 8.7 | Incorrect Permission Assignment for Critical Resource in | Not exploited |
See a Google CVE's exploit risk spike before it becomes a headline.
Get EPSS spike alertsWhy the Viidure Dashcam App Flaws Matter
Drivers use the app to view and download footage from their dashcams. CISA lists the Transportation Systems sector and says the product is deployed worldwide. Both flaws hit the shared cloud storage behind the whole platform, not just one device. As a result, a single weakness affects every user at once.
How the Attacks Work
Hardcoded Credentials (CVE-2026-96587, CVSS 10.0)
The app ships with fixed cloud storage keys inside its code. According to CISA, “these credentials provide full access to critical platform storage, including the ability to read, modify, or delete operational files such as firmware and application binaries.” That opens the door to tampered firmware updates. Anyone who unpacks the app could pull out the keys, since they sit in plaintext.
Public Cloud Storage (CVE-2026-94204, CVSS 7.5)
The storage bucket also allows public reads. CISA warns that “sensitive user records, live dashcam footage, application packages, and firmware files are exposed to anyone on the internet.”
Affected Versions and Exploitation Status
All versions of the Viidure dashcam app up to 3.3.1.260403 are affected. Bugrahan Karahan reported the flaws to CISA. CISA states that “no known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.” No public proof-of-concept has been confirmed either.
Patch and Mitigation Steps
No patch exists. The CISA Viidure advisory states that “Viidure did not respond to CISA’s coordination attempts.” Users should contact Viidure support for more information. Until a fix arrives, avoid storing sensitive footage through the Viidure dashcam app, and consider removing it.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!