Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
Viidure did not respond to CISA's coordination attempts. Users of affected versions of the Viidure Dashcam Android Application are advised to contact Viidure customer support for additional information https://viidure.app/. https://viidure.app/
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 29 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 29 Sep 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Viidure Android application embeds permanent, plaintext cloud storage credentials within its compiled code. These credentials provide full access to critical platform storage, including the ability to read, modify, or delete operational files such as firmware and application binaries. | |
| Title | Use of Hard-coded Credentials in Viidure Dashcam Android Application | |
| Weaknesses | CWE-798 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-09-29T21:02:00.222Z
Reserved: 2026-09-24T16:42:35.652Z
Link: CVE-2026-96587
Updated: 2026-09-29T21:00:17.404Z
Status : Awaiting Analysis
Published: 2026-09-29T21:19:39.987
Modified: 2026-09-29T22:19:05.860
Link: CVE-2026-96587
No data.
OpenCVE Enrichment
No data.
-
CWE-798
Use of Hard-coded Credentials