Plaintext Credentials Vulnerability in Viidure Android Application
CVE-2026-96587

10CRITICAL

Key Information:

Vendor

Viidure

Vendor
CVE Published:
29 September 2026

What is CVE-2026-96587?

The Viidure Android application contains a significant security flaw where hardcoded cloud storage credentials are embedded in its compiled code. This exposure allows unauthorized users to gain complete access to critical storage resources, enabling them to read, alter, or remove vital operational files, such as firmware and application binaries. The presence of these plaintext credentials within the app poses a substantial risk to the integrity and security of the platform, necessitating immediate attention from users and developers.

Affected Version(s)

Dashcam Android Application 0 <= 3.3.1.260403

References

CVSS V4

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Bugrahan Karahan
.