Skip to content

Executive Summary

The Viidure Dashcam Android Application, specifically versions up to 3.3.1.260403, is affected by two critical vulnerabilities. The first vulnerability, CVE-2026-94204, involves a misconfiguration of the central cloud storage backend, granting public-read permissions to all stored objects, exposing user records, footage, application packages, and firmware files. The second vulnerability, CVE-2026-96587, stems from embedding permanent, plaintext cloud storage credentials within the application's compiled code, which allows full access to critical platform storage, including operational files like firmware and binaries. These vulnerabilities have a combined potential impact rated as HIGH or CRITICAL severity under the CVSS scoring system.
Viidure provided no planned fixes for these issues and did not respond to coordination attempts from CISA. Users of the affected versions are advised to seek information directly from Viidure customer support. The context involves transportation systems, with deployment worldwide, and the company headquarters located in China. Recommended defensive practices suggested by CISA include minimizing network exposure, using firewalls, employing VPNs for remote access, and performing risk assessments before implementing security measures.

Facts Only

* Affected products include the Viidure Dashcam Android Application versions less than or equal to 3.3.1.260403.
* Vulnerability CVE-2026-94204 involves public-read permissions on the central cloud storage backend, exposing user records, footage, application packages, and firmware files.
* Vulnerability CVE-2026-96587 involves embedding permanent, plaintext cloud storage credentials within the compiled code of the Android application.
* CVE-2026-94204 is associated with CWE-732 (Incorrect Permission Assignment for Critical Resource).
* CVE-2026-96587 is associated with CWE-798 (Use of Hard-coded Credentials).
* The vulnerabilities are present in the Viidure Dashcam Android Application version <=3.3.1.260403.
* CVSS scores for CVE-2026-94204 range from 7.5 (CVSS 3.1) to 8.7 (CVSS 4.0).
* CVSS scores for CVE-2026-96587 range from 10 (CVSS 3.1) to 10 (CVSS 4.0).
* Viidure has not planned a fix and did not respond to CISA coordination attempts.
* The affected system is related to transportation systems deployed worldwide, with the company headquarters in China.

Full Take

The existence of both a public misconfiguration (CVE-2026-94204) and hardcoded secrets (CVE-2026-96587) within a product intended for critical infrastructure implies a systemic failure in the secure development lifecycle, rather than a single oversight. The fact that these severe flaws remain unpatched and unaddressed by the vendor suggests a pattern where security considerations are secondary to deployment velocity or profit maximization in certain sectors. This situation forces an analysis of accountability: who bears the cost when embedded credentials facilitate total control over operational data and firmware?
The CISA recommendations focus heavily on network isolation, suggesting that technical fixes alone are insufficient; the risk is fundamentally infrastructural. The pattern here is one where complex systems relying on remote access or cloud services introduce exploitable surfaces, and the remediation often shifts responsibility onto the end-user to perform burdensome defensive actions, rather than demanding vendor accountability for secure defaults. The juxtaposition of global deployment with specific location data introduces a geopolitical layer: vulnerabilities in critical transportation technology are known to exist across jurisdictions, and the lack of vendor response highlights an asymmetry in threat disclosure and mitigation efforts between the vendor and external oversight bodies.
What does this mean for agency? It demonstrates that security is not a feature added at the end; it must be foundational. If systemic flaws like these persist unnoticed until reported by external entities, it reinforces the notion that user responsibility is often the last line of defense against poorly secured digital assets deployed in sensitive environments. The missing piece is the mechanism ensuring external coordination translates into enforceable security standards for embedded systems. What protocols are necessary to ensure that vulnerability disclosures trigger mandatory, rapid patching and accountability across global deployments of critical technology?

From the original · CISA ICS Advisories

Summary Successful exploitation of these vulnerabilities could allow attackers to access, modify, or delete sensitive user data and critical system files, potentially compromising the operation of the entire platform.
Read the full story at cisa.gov

Sentinel — Human

Confidence

This text reads like a formal security advisory derived directly from vulnerability disclosure data, characterized by precise technical details and authoritative source referencing.

Signals Detected
low severity: Moderate sentence length variance; structured and informative tone.
low severity: Strong, functional coherence focused purely on technical reporting and attribution.
low severity: Structured presentation of CVEs, metrics, and CISA recommendations follows a clear forensic pattern.
low severity: Specific citation of CVEs, CVSS scores, company names (Viidure), and references to specific government bodies (CISA) suggests grounded, factual reporting.
Human Indicators
The inclusion of specific, dated CVE identifiers (CVE-2026-94204, CVE-2026-96587) and direct links to CISA resources indicates sourcing from official security advisories.
The structured presentation with tables and explicit mitigation advice follows the style of formal security reporting, not typical narrative journalism.
Viidure Dashcam Android Application | Huntaegis