securityonline.info 1 Oct 2026, 01:00 UTC

CISA Warns Viidure Dashcam Flaws Could Expose Global Cloud Data

CISA Warns Viidure Dashcam Flaws Could Expose Global Cloud Data
CyberSIXT Evidence Panel
CISA KEV Not in KEV
Patch Patch Status Unknown

CISA has warned about two critical flaws in the Viidure dashcam Android app, disclosed in advisory ICSA-26-272-07 dated 29 September 2026. The most severe issue, CVE-2026-96587, scores CVSS 10.0 and involves hardcoded cloud storage credentials embedded in the app’s code. These plaintext keys grant full access to the platform’s storage, enabling reading, modification or deletion of operational files such as firmware and application binaries, with the potential to tamper with firmware updates.

The second flaw, CVE-2026-94204, carries a CVSS of 7.5 and concerns incorrect permissions on a critical resource within a publicly readable cloud storage bucket, exposing sensitive user records, live footage, application packages and firmware files to anyone on the internet. Both flaws affect all Viidure dashcam app versions up to 3.3.1.260403 and the issues are described as affecting the shared cloud storage behind the entire platform rather than a single device.

Evidence from CISA indicates that Viidure has not provided a fix to date and did not respond to coordination attempts. At the time of the advisory, there were no known public exploits or confirmed exploitation reported to CISA, nor public PoCs confirmed. There is no available patch yet. Practically, users are advised to contact Viidure support and, until a fix arrives, to avoid storing sensitive footage through the Viidure dashcam app and consider removing it.

The advisory stresses the global deployment of the Viidure system in the Transportation Systems sector, underscoring that a single vulnerability could impact all users.

View full article

Article by CyberSIXT