Skip to content

Security1 publisher2 min readPublished

Viidure dashcam platform exposes live footage and firmware through a publicly readable bucket

CISA says Viidure's dashcam platform keeps user records, live footage and firmware in a cloud bucket that anyone on the internet can read. Viidure did not answer CISA and plans no fix, so the advisory can only point users to the vendor's support page.

The Watch · Security desk

What happened

  • The Android app also carries permanent, plaintext cloud-storage credentials in its compiled code that can read, modify or delete the platform's firmware and application binaries.
  • The flaws are tracked as CVE-2026-94204 and CVE-2026-96587 and affect Viidure Dashcam Android Application versions up to and including 3.3.1.260403.
  • CISA lists the product under the Transportation Systems sector, deployed worldwide, from a company headquartered in China.
  • Researcher Bugrahan Karahan reported both vulnerabilities to CISA.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • capability Anyone holding a copy of the app can go from reading the platform's files to replacing or deleting its firmware and app binaries.
  • exposure The misconfigured store is shared by the whole platform, so a single reader can collect every stored user record and clip in one pass.
  • decision Transportation fleets running the app have to decide whether to keep a product whose vendor did not engage with CISA and whose two flaws will not be patched.

Every copy of the Android app holds the storage credentials, because they are compiled into it [1]. The open bucket also stores the platform's application packages next to the records and footage [4]. Anyone can read that bucket [3]. Writing to it or deleting from it takes a copy of the app and the work of extracting the credentials. No account or intrusion is involved [1]. CISA classes the two flaws as CWE-732, incorrect permission assignment for a critical resource, and CWE-798, use of hard-coded credentials [12].

According to CISA, exploitation could let attackers access, modify or delete user data and critical system files, "potentially compromising the operation of the entire platform" [2]. The advisory does not say whether dashcams fetch firmware from that bucket, or whether they verify a signature before installing it. A tampered file reaches a vehicle only if the first is true and the second is not.

The advisory's remedy for users is to contact Viidure customer support [7]. The rest of CISA's guidance is its standard list for control systems: keep devices off the internet, put them behind firewalls isolated from business networks, and use VPNs for remote access [11]. Each of those protects a network the operator runs. The exposed store is the platform's central backend [3].

That leaves users one control of their own: whether to keep using the product. Stopping limits what a fleet adds to the bucket from that day on. Records and footage already stored there stay open to any reader for as long as the permissions stand [4].

CISA says no known public exploitation specifically targeting these flaws has been reported to it [8]. The bucket answers any requester [4], so a plain request is enough to read it.

What to watch

  • Any reply from Viidure to CISA, or a change to the bucket's permissions, that would move the advisory off 'no fix planned'.
  • Evidence that dashcams download firmware from the exposed storage without signature checks, which would carry file tampering onto devices.
  • A CISA revision to the advisory that reports exploitation of CVE-2026-94204 or CVE-2026-96587.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories