VYPR
advisoryPublished Sep 29, 2026· 1 source

Critical Vulnerabilities in Viidure Dashcam Android App Expose User Data

CISA alerts users to two critical vulnerabilities in the Viidure Dashcam Android Application, versions up to 3.3.1.260403, due to misconfigured cloud storage and hard-coded credentials.

CISA has issued a critical advisory detailing two severe vulnerabilities affecting the Viidure Dashcam Android Application, specifically versions up to and including 3.3.1.260403. These flaws, identified as CVE-2026-94204 and CVE-2026-96587, pose significant risks to user privacy and system integrity, as they allow for unauthorized access, modification, or deletion of sensitive data and critical system files.

The first vulnerability, CVE-2026-94204, stems from a misconfiguration in the application's central cloud storage backend. This backend was found to have public-read permissions, meaning any individual with internet access could potentially view all stored objects. This includes sensitive user records, live dashcam footage, application packages, and firmware files, leaving users' data exposed without any form of authentication.

Compounding the risk, CVE-2026-96587 involves the use of hard-coded cloud storage credentials within the application itself. These credentials, embedded directly in the compiled code, grant attackers full access to the critical platform storage. This allows for not only reading but also modifying or deleting essential operational files, such as firmware and application binaries, which could lead to complete system compromise or manipulation.

The potential impact of these vulnerabilities is substantial. Attackers could gain unfettered access to private user data, including potentially sensitive video footage. Furthermore, the ability to modify or delete critical files could disrupt the operation of the dashcam platform entirely, or worse, allow for the deployment of malicious updates or firmware.

These vulnerabilities affect the Transportation Systems sector, with deployments reported worldwide. The company's headquarters are located in China. The CVSS v3.1 base score for CVE-2026-94204 is 7.5 (HIGH), while CVE-2026-96587 is rated a critical 10.0 (CRITICAL), highlighting the severity of the security flaws.

Unfortunately, Viidure has not provided a fix for these vulnerabilities and did not respond to CISA's coordination attempts. Users of the affected versions of the Viidure Dashcam Android Application are advised to contact Viidure customer support for further information, though no immediate remediation is planned by the vendor.

CISA recommends that users minimize network exposure for all control system devices, ensuring they are not accessible from the internet and are located behind firewalls. Secure remote access methods like VPNs should be used when necessary, with the understanding that VPNs themselves require up-to-date security. Organizations are urged to perform thorough impact and risk assessments before implementing any defensive measures.

While no known public exploitation has been reported to CISA at this time, the critical nature of these vulnerabilities and the lack of a vendor-provided fix necessitate immediate attention from users and administrators of the Viidure Dashcam Android Application to mitigate potential risks.

Synthesized by Vypr AI