# Viidure Dashcam app exposes cloud storage, credentials

Published: 2026-09-29 · Severity: routine · Sectors: transportation
Canonical: https://vorant.io/reports/630fdac9-3b88-5836-8013-e98781ab28c5/viidure-dashcam-app-exposes-cloud-storage-credentials

> Viidure Android dashcam app has a public-read cloud storage bucket and hardcoded credentials, exposing user data and firmware; no fix planned.

CISA published an advisory for the Viidure Dashcam Android Application (versions <=3.3.1.260403) detailing two vulnerabilities affecting the platform's cloud backend. CVE-2026-94204 stems from a misconfigured central cloud storage bucket with public-read permissions, exposing sensitive user records, live dashcam footage, application packages, and firmware files to anyone on the internet. CVE-2026-96587 involves hardcoded, plaintext cloud storage credentials embedded in the compiled Android app, which grant full read/write/delete access to operational storage including firmware and app binaries.

Viidure, headquartered in China with worldwide deployment in the Transportation Systems sector, did not respond to CISA's coordination attempts, and no fix is planned for either issue. Affected users are directed to contact Viidure support directly. There is no evidence of active exploitation reported to CISA at this time, but the exposure is straightforward to discover and abuse given the public bucket and embedded static credentials, presenting an ongoing risk to user privacy (footage, personal data) and platform integrity (firmware/app tampering).

Defenders and consumers using this dashcam application should treat any data uploaded via the app as potentially exposed, avoid relying on it for sensitive footage storage, and monitor for anomalous firmware or app updates. Since no vendor fix is forthcoming, discontinuing use or isolating the device from sensitive accounts/networks is the practical mitigation.

## Mentioned in this report

- Vulnerabilities: CVE-2026-94204, CVE-2026-96587

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-07

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/630fdac9-3b88-5836-8013-e98781ab28c5/viidure-dashcam-app-exposes-cloud-storage-credentials.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
