- CISA reports two flaws in the Viidure Dashcam Android Application, versions 3.3.1.260403 and earlier. They expose a shared cloud storage bucket holding user records and live dashcam footage.
- CISA says Viidure did not respond to coordination attempts and lists no fix planned. No public exploitation has been reported to CISA.
- Organisations using the app should ask who owns the risk, what data sits in the vendor's storage, and whether they can stop using it.
An app is only as private as the storage behind it
Most people judge a mobile app by what they see on screen. The better question is where its data lives and who can open that door. A new advisory on the Viidure Dashcam Android Application shows why.
The lesson here is simple. When one shared storage bucket is open and the app carries keys to it, the exposure covers everything the platform holds. The user only ever sees the app.
What CISA reported
The US Cybersecurity and Infrastructure Security Agency (CISA) published the advisory on September 29, 2026. It covers Viidure Dashcam Android Application versions 3.3.1.260403 and earlier. It lists two flaws: CVE-2026-94204 and CVE-2026-96587. It places the product in the Transportation Systems sector.
Researcher Bugrahan Karahan reported both flaws to CISA.
How the two flaws work
The first flaw is a permissions error, filed as CWE-732. CISA says the main cloud storage for the whole dashcam platform is set to public-read. That means anyone on the internet can read what is stored there.
The storage is shared by the whole platform. So the open door leads to a lot. CISA names sensitive user records, live video from the cameras, the files that install the app, and the software that runs the devices. Picture one warehouse with its front door propped open.
The second flaw is hard-coded credentials, filed as CWE-798. CISA says the Android app carries permanent storage logins inside its compiled code. They are in plaintext. That means the password is stored as readable text, with no protection.
CISA says these logins give full access to key platform storage. A person holding one could swap out the device software or the app's program files, or remove them. Firmware is the software that runs the device itself.
Put the two flaws together. The first lets anyone look at the data. The second supplies a key that can also change or erase it. Because the key is inside the app's code, it travels with the app.
The part that matters most: no fix is planned
For both flaws, CISA states "No fix planned." It also says Viidure did not respond to its attempts to coordinate. CISA tells users of affected versions to contact Viidure customer support.
That leaves customers holding a risk they cannot repair. Only the vendor can change the storage settings and replace the embedded key. A customer can do neither.
CISA also says no known public exploitation of these flaws has been reported to it. That reflects what CISA has been told. It does not prove the data has gone unread.
Questions the advisory leaves open
The advisory does not say how many users or devices are affected. It does not say whether devices check firmware files before installing them. That second point matters, because the logins allow firmware to be changed. The advisory is silent on it, so teams should ask rather than assume.
What leaders should do
If your organisation uses dashcams or similar apps, start with an inventory. Put these questions to your security team.
First, does anyone in the business use the Viidure app, on company phones or in company vehicles? Second, what footage and records would sit in the vendor's storage if they did? Third, can we stop using the product, and who decides? Fourth, what do our contracts say about vendors who go silent on a security report?
CISA's mitigation advice is its standard guidance for industrial control systems. It tells teams to minimize network exposure and take defensive measures. That guidance does not address a misconfiguration on the vendor's side. CISA also reminds teams to assess impact first. For a product with no fix planned, the real choice may be between accepting the exposure and replacing the product.
A vendor that stays silent after a coordinated report has made a decision for you. The sensible response is to make your own.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: CISA.





