Critical Vulnerabilities in Viidure Dashcam Android Application
The Viidure Dashcam Android application (<= 3.3.1.260403) contains two high-risk vulnerabilities, including hard-coded cloud credentials and misconfigured public cloud storage, that expose sensitive user data and platform firmware.
The Viidure Dashcam Android application, used globally in the transportation sector, contains two critical security flaws identified as CVE-2026-94204 and CVE-2026-96587. The vulnerabilities originate from a combination of poor development practices and backend misconfiguration. Specifically, the application embeds hard-coded, plaintext cloud storage credentials within its compiled binaries (CVE-2026-96587), providing attackers with full read, write, and delete capabilities over the platform's cloud storage. Furthermore, the associated backend storage is misconfigured with public-read permissions (CVE-2026-94204), leading to the exposure of private user records, live dashcam footage, and critical firmware files. These vulnerabilities pose a significant threat to user privacy and system integrity, potentially allowing attackers to compromise the entire dashcam ecosystem. The vendor, Viidure, has not responded to coordination attempts, and no fixes are currently planned for the affected versions.
Impact
The impact of these vulnerabilities is substantial, as they expose private user information, including live footage from dashcams, to unauthorized actors globally. Successful exploitation allows for the modification or deletion of platform-critical files, such as firmware, which could lead to mass service disruption or the injection of malicious updates across the user base. As the platform is used worldwide in transportation systems, the risks include widespread privacy violations and the potential for large-scale operational sabotage.
Recommendation
Prioritized, concrete actions for organizations using the Viidure platform:
- Immediately restrict all network access to Viidure cloud resources if integrated into corporate environments, as no vendor patch is available.
- Evaluate organizational risk regarding the usage of this application, given the lack of a vendor-provided remediation plan.
- Isolate any mobile devices running the Viidure Dashcam application from sensitive enterprise networks and implement strict egress filtering to prevent unauthorized data exfiltration to the identified cloud storage backends.
- Consult the vendor at https://viidure.app/ for any potential updates or guidance, though no official fix is currently available.
Immediate actions
Isolate devices running the affected application from business networks
Mitigations
Monitor for or block access to the cloud storage backends utilized by the Viidure platform
CVE-2026-94204