Home › Intelligence › Brief
VULNERABILITY BRIEF🔴 Critical Vulnerability

Critical Public‑Read Cloud Bucket & Hard‑Coded Credentials in Viidure Dashcam Android App (CVE‑2026‑94204, CVE‑2026‑96587) Expose User Data

Two CVEs in Viidure’s Dashcam Android application (≤3.3.1.260403) grant unrestricted internet access to the platform’s cloud storage and embed hard‑coded credentials. Exploitation could let threat actors view, modify, or delete live footage, user records, and firmware, jeopardizing transportation‑system integrity. The issue underscores the need for demonstrable access‑control evidence in audit‑ready environments.

LiveThreat™ Intelligence · 📅 September 29, 2026· 📰 cisa.gov
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
3 recommended
📰
Source
cisa.gov

Critical Public‑Read Cloud Bucket & Hard‑Coded Credentials in Viidure Dashcam Android App (CVE‑2026‑94204, CVE‑2026‑96587)

What It Is – Two CVEs affect the Viidure Dashcam Android application (versions ≤ 3.3.1.260403). CVE‑2026‑94204 is a public‑read misconfiguration of the central cloud‑storage bucket; CVE‑2026‑96587 embeds hard‑coded credentials in the app binary. Both give an attacker unrestricted read/write access to user data, live footage, and firmware.

Exploitability – CVSS 3.1 base score 10.0 (Critical). Public bucket can be accessed without authentication; hard‑coded credentials enable authenticated API calls. No public exploit code is required – the flaws are trivially exploitable by anyone who discovers the bucket URL.

Affected Products – Viidure Dashcam Android Application ≤ 3.3.1.260403 (global deployment, transportation‑system customers).

Why It Matters for Trust & Control Assurance

  • Access‑control evidence: Public‑read storage violates the control objective of restricting access to critical resources; auditors expect verifiable permission settings.
  • Credential lifecycle: Hard‑coded secrets bypass proper credential‑management processes, eroding confidence in the vendor’s security hygiene.
  • Continuous monitoring: Demonstrable, automated checks of cloud permissions and secret inventories are now a baseline requirement for transportation‑sector contracts that demand audit‑ready evidence.

Recommended Actions

  • Immediately revoke public‑read ACLs on the cloud bucket and enforce least‑privilege IAM policies.
  • Rotate all embedded credentials and replace them with a secure, runtime‑generated secret store.
  • Deploy automated permission‑drift detection and integrate findings into your control‑mapping evidence repository.
  • Contact Viidure for a formal remediation patch; if none is forthcoming, evaluate alternative dashcam providers.

Source: CISA Advisory – ICSA‑26‑272‑07

📰 Original Source
https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-07 ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →