Critical Public‑Read Cloud Bucket & Hard‑Coded Credentials in Viidure Dashcam Android App (CVE‑2026‑94204, CVE‑2026‑96587)
What It Is – Two CVEs affect the Viidure Dashcam Android application (versions ≤ 3.3.1.260403). CVE‑2026‑94204 is a public‑read misconfiguration of the central cloud‑storage bucket; CVE‑2026‑96587 embeds hard‑coded credentials in the app binary. Both give an attacker unrestricted read/write access to user data, live footage, and firmware.
Exploitability – CVSS 3.1 base score 10.0 (Critical). Public bucket can be accessed without authentication; hard‑coded credentials enable authenticated API calls. No public exploit code is required – the flaws are trivially exploitable by anyone who discovers the bucket URL.
Affected Products – Viidure Dashcam Android Application ≤ 3.3.1.260403 (global deployment, transportation‑system customers).
Why It Matters for Trust & Control Assurance
- Access‑control evidence: Public‑read storage violates the control objective of restricting access to critical resources; auditors expect verifiable permission settings.
- Credential lifecycle: Hard‑coded secrets bypass proper credential‑management processes, eroding confidence in the vendor’s security hygiene.
- Continuous monitoring: Demonstrable, automated checks of cloud permissions and secret inventories are now a baseline requirement for transportation‑sector contracts that demand audit‑ready evidence.
Recommended Actions
- Immediately revoke public‑read ACLs on the cloud bucket and enforce least‑privilege IAM policies.
- Rotate all embedded credentials and replace them with a secure, runtime‑generated secret store.
- Deploy automated permission‑drift detection and integrate findings into your control‑mapping evidence repository.
- Contact Viidure for a formal remediation patch; if none is forthcoming, evaluate alternative dashcam providers.
Source: CISA Advisory – ICSA‑26‑272‑07