Overview
CISA has published ICS advisory ICSA-26-272-07, disclosing CVE-2026-96587, a maximum-severity vulnerability in the Viidure Dashcam Android application — the companion app used to pair with, configure, and manage Viidure's dashcam product line. The flaw carries a CVSS 3.1 score of 10.0, the highest possible rating, with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H: exploitable over the network, with low attack complexity, no privileges required, no user interaction, and complete impact to confidentiality, integrity, and availability, with a Scope Changed designation reflecting that the compromise extends well beyond the app itself.
According to CISA's advisory, published September 29, 2026, the Viidure Android app "embeds permanent, plaintext cloud storage credentials within its compiled code." These are not per-user or per-device tokens — they are static access keys baked into every installed copy of the application binary, and they grant full access to the platform's backend cloud storage, "including the ability to read, modify, or delete operational files such as firmware and application binaries." The issue is tracked under CWE-798 — Use of Hard-coded Credentials.
CISA's advisory also lists a closely related, companion flaw: CVE-2026-94204 (CVSS 7.5, High), in which the same cloud storage backend is separately "misconfigured with public-read permissions, allowing unrestricted access to all stored objects." Individually, either issue is serious. Together, they compound: the public-read misconfiguration means anyone can already browse the bucket's contents without credentials, while the hardcoded keys in CVE-2026-96587 hand out write and delete access to the same storage — turning a passive data-exposure problem into a platform-wide tampering and supply-chain risk.
Viidure is listed in CISA's advisory under the Transportation Systems critical infrastructure sector, with products deployed worldwide and the company headquartered in China. Perhaps most notably, CISA states that Viidure did not respond to coordination attempts, and as a result no fix is planned. There is no patched version to upgrade to, and affected users are directed to contact Viidure's customer support directly for further information. Third-party trackers list the affected release range as version 3.3.1.260403 and earlier — effectively all currently known builds of the app.
Technical Details
| Attribute | Value |
|---|---|
| CVE ID | CVE-2026-96587 |
| Severity | Critical |
| CVSS Score | 10.0 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) |
| Attack Vector | Network |
| Authentication | Not required |
| Privileges Required | None (PR:N) — no user interaction needed (UI:N) |
| CWE | CWE-798 — Use of Hard-coded Credentials |
| Component/Function | Viidure Dashcam Android application, compiled binary (embedded cloud storage keys) |
| Affected Versions | ≤ 3.3.1.260403 |
| Related Advisory | CVE-2026-94204 (CVSS 7.5) — cloud storage bucket misconfigured with public-read access (CWE-732) |
| Advisory | CISA ICSA-26-272-07, published September 29, 2026 |
| Exploit Status | Not listed on CISA's KEV catalog; no confirmed public proof-of-concept as of September 30, 2026 |
How It Works
The vulnerability class
CWE-798 covers software that relies on fixed, embedded credentials — API keys, passwords, or access tokens — instead of provisioning secrets per-device or per-user at runtime. Hardcoded credentials are considered one of the most severe classes of software weakness precisely because compiled application binaries are not secret: any party who can download the app can, with standard reverse-engineering tooling, recover strings and constants embedded at build time. There is no way to "rotate" a leaked key that is baked into every copy of a shipped app without a full re-release, and until that happens, every installation of the app is a working credential.
The attack chain
- An attacker downloads the Viidure Android app APK, either from an official store listing or a third-party mirror.
- Using standard, freely available Android reverse-engineering tools (e.g.
apktoolorjadx), the attacker decompiles the app and extracts the plaintext cloud storage access key and secret embedded in the compiled code. This step requires no authentication to the app and no interaction from any legitimate user — the credentials are static and identical across installs. - The attacker uses the extracted credentials directly against the cloud storage provider's API, with nothing more than standard network connectivity.
- Because the storage backend is shared infrastructure for the entire Viidure platform — not scoped per user or per device — a single extraction compromises the storage layer for every Viidure customer, not just the attacker's own account. This is the practical meaning of the CVSS Scope Changed rating: the blast radius extends past the vulnerable app into infrastructure the app was never meant to expose.
- With full read, write, and delete access confirmed, an attacker can enumerate and download stored objects (including, per CISA and independent analysis, user records, dashcam footage, application packages, and firmware images), overwrite those same files with malicious payloads, or delete them outright.
Why the pairing with CVE-2026-94204 matters
CVE-2026-94204 already leaves the same bucket world-readable with no credentials at all, meaning sensitive data such as live dashcam footage was exposed to anyone before CVE-2026-96587 is even factored in. What the hardcoded keys add is write and delete capability. An attacker who can modify or replace the firmware and application binaries stored in that bucket is positioned for a supply-chain attack: if devices or app installs pull updates from that same storage location, a tampered firmware image could be distributed to real Viidure hardware in the field. Combined with the advisory's classification under the Transportation Systems sector and worldwide deployment footprint, the practical risk spans both privacy (footage and user data exposure) and operational integrity (tampered firmware reaching deployed dashcams).
Impact Assessment
| Impact Area | Description |
|---|---|
| Credential Exposure | Static, plaintext cloud storage keys embedded in every copy of the app binary, trivially recoverable via standard reverse engineering — no working exploit sophistication required |
| Confidentiality | Rated High — full read access to platform storage, including user records and dashcam footage, compounded by the public-read bucket in CVE-2026-94204 |
| Integrity | Rated High — attackers can modify or overwrite operational files, including firmware and application binaries hosted in the same storage |
| Availability | Rated High — delete access allows an attacker to remove operational files outright, disrupting app updates or device functionality |
| Supply Chain Risk | Write access to firmware and application binaries in shared storage creates a path to distributing tampered updates to deployed devices |
| Scope | Changed (S:C) — compromise extends beyond the vulnerable app into the shared cloud storage backend serving the entire platform, affecting all Viidure customers, not just the device owner who installed the app |
Recommendations
For Viidure dashcam owners
- Treat the Viidure Android companion app as untrusted until the vendor confirms a fix — CISA reports Viidure has not responded to coordination attempts and no patched version currently exists.
- Limit or discontinue cloud-connected features of the dashcam where possible, since the compromised credentials grant access to cloud-stored data and firmware, not just the local app.
- Monitor for unusual device behavior, including unexpected firmware prompts or app updates, which could indicate tampering via the compromised storage backend.
- Contact Viidure customer support directly for the latest guidance, as instructed in CISA's advisory.
For fleet operators and transportation-sector IT/security teams
- Inventory any Viidure dashcam deployments in vehicle fleets and flag them as affected by both CVE-2026-96587 and CVE-2026-94204.
- Restrict network egress from managed devices where feasible, and avoid relying on vendor cloud sync for sensitive footage until credentials are rotated and the bucket is properly secured.
- Apply CISA's standard ICS mitigations: minimize network exposure for control-adjacent systems, place management interfaces behind firewalls and network segmentation, and use VPNs for any required remote access rather than exposing services directly.
- Assume any data previously stored via the app's cloud sync has been exposed, given the combination of a public-read bucket and now-public hardcoded write credentials, and handle any privacy notifications accordingly.
For security teams generally
- Treat this as a case study, not an isolated incident — hardcoded cloud credentials in consumer and IoT-adjacent mobile apps are a recurring pattern (CWE-798 findings have surfaced repeatedly across other consumer camera and IoT app ecosystems in 2026).
- Audit any internally developed or vendor-supplied mobile apps for embedded static secrets using APK decompilation and secret-scanning tooling as part of routine app security review.
- Track this advisory for updates — since Viidure has not engaged with CISA, remediation (if it ever arrives) is more likely to surface through a silent app update than a formal advisory revision.
Key Takeaways
- CVE-2026-96587 is a CVSS 10.0, maximum-severity hardcoded credentials flaw (CWE-798) in the Viidure Dashcam Android application, disclosed by CISA on September 29, 2026 via advisory ICSA-26-272-07.
- The app embeds permanent, plaintext cloud storage credentials directly in its compiled binary, granting full read, modify, and delete access to platform-wide storage — including firmware and application binaries — to anyone who reverse-engineers the app.
- A closely related flaw, CVE-2026-94204 (CVSS 7.5), separately leaves the same storage bucket public-read, compounding the exposure: data was already accessible without credentials, and the hardcoded keys add write/delete capability on top.
- No authentication or user interaction is required to exploit CVE-2026-96587, and the Scope Changed rating reflects that the impact extends beyond the app to the entire shared cloud storage backend serving all Viidure customers.
- Viidure did not respond to CISA's coordination attempts, and no fix is currently planned — affected users have no patched version to move to and should treat the app's cloud-connected features as compromised.
- Given write access to firmware and application binaries, the flaw creates a credible supply-chain tampering path, and Viidure's listing under CISA's Transportation Systems sector with worldwide deployment raises the stakes beyond a typical consumer privacy issue.
Sources
- CISA — ICS Advisory ICSA-26-272-07: Viidure Dashcam Android Application
- NVD — CVE-2026-96587
- Strix.ai — CVE-2026-96587: Dashcam Android Application Hardcoded Credentials
- The Hacker Wire — CVE-2026-96587: Viidure Android App Hardcoded Credentials Expose Critical Platform Storage
CosmicBytez Labs will update this advisory if Viidure responds to CISA's coordination attempts or if a patched version becomes available.