{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/viidure/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Viidure Dashcam Android Application (\u003c= 3.3.1.260403)"],"_cs_severities":["critical"],"_cs_tags":["iot","mobile-app","cve","transportation"],"_cs_type":"advisory","_cs_vendors":["Viidure"],"content_html":"\u003cp\u003eThe Viidure Dashcam Android application, used globally in the transportation sector, contains two critical security flaws identified as CVE-2026-94204 and CVE-2026-96587. The vulnerabilities originate from a combination of poor development practices and backend misconfiguration. Specifically, the application embeds hard-coded, plaintext cloud storage credentials within its compiled binaries (CVE-2026-96587), providing attackers with full read, write, and delete capabilities over the platform's cloud storage. Furthermore, the associated backend storage is misconfigured with public-read permissions (CVE-2026-94204), leading to the exposure of private user records, live dashcam footage, and critical firmware files. These vulnerabilities pose a significant threat to user privacy and system integrity, potentially allowing attackers to compromise the entire dashcam ecosystem. The vendor, Viidure, has not responded to coordination attempts, and no fixes are currently planned for the affected versions.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe impact of these vulnerabilities is substantial, as they expose private user information, including live footage from dashcams, to unauthorized actors globally. Successful exploitation allows for the modification or deletion of platform-critical files, such as firmware, which could lead to mass service disruption or the injection of malicious updates across the user base. As the platform is used worldwide in transportation systems, the risks include widespread privacy violations and the potential for large-scale operational sabotage.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized, concrete actions for organizations using the Viidure platform:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately restrict all network access to Viidure cloud resources if integrated into corporate environments, as no vendor patch is available.\u003c/li\u003e\n\u003cli\u003eEvaluate organizational risk regarding the usage of this application, given the lack of a vendor-provided remediation plan.\u003c/li\u003e\n\u003cli\u003eIsolate any mobile devices running the Viidure Dashcam application from sensitive enterprise networks and implement strict egress filtering to prevent unauthorized data exfiltration to the identified cloud storage backends.\u003c/li\u003e\n\u003cli\u003eConsult the vendor at \u003ca href=\"https://viidure.app/\"\u003ehttps://viidure.app/\u003c/a\u003e for any potential updates or guidance, though no official fix is currently available.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-29T16:25:19Z","date_published":"2026-09-29T16:25:19Z","id":"https://feed.craftedsignal.io/briefs/2026-09-viidure-dashcam-vulnerabilities/","summary":"The Viidure Dashcam Android application (\u003c= 3.3.1.260403) contains two high-risk vulnerabilities, including hard-coded cloud credentials and misconfigured public cloud storage, that expose sensitive user data and platform firmware.","title":"Critical Vulnerabilities in Viidure Dashcam Android Application","url":"https://feed.craftedsignal.io/briefs/2026-09-viidure-dashcam-vulnerabilities/"}],"language":"en","title":"CraftedSignal Threat Feed - Viidure","version":"https://jsonfeed.org/version/1.1"}