AI analysis
The central cloud storage backend for the Viidure dashcam platform is misconfigured with public-read permissions, so anyone on the internet can access stored objects without authentication. Because the bucket is shared platform storage, sensitive user records, live dashcam footage, application packages, and firmware files are exposed (CWE-732, incorrect permission assignment). An attacker gains high confidentiality impact only; published CVSS 4.0 is 8.7, with no integrity or availability impact and no privileges or user interaction required. Users of the Viidure Dashcam Android application and anyone whose data resides in that shared backend are affected; no affected version range is stated in the advisory data. The CVE is not listed in CISA KEV and no public proof-of-concept is known.
What to do: Immediately remove public-read and anonymous listing from the platform storage bucket and restrict every object to authenticated, least-privilege access. Treat previously exposed user records, dashcam footage, application packages, and firmware as compromised: notify affected users, rotate any secrets found in the bucket, and reissue or resign firmware and app packages if their integrity cannot be assured. Verify the Android app and backend no longer depend on world-readable object URLs before restoring normal access.
Affected
| Viidure Dashcam platform central cloud storage (Viidure Dashcam Android Application) | — |
Estimated exposure
—No basis for an estimate.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
The central cloud storage backend for the entire dashcam platform is misconfigured with public-read permissions, allowing unrestricted access to all stored objects. Because this bucket serves as shared storage for the platform, sensitive user records, live dashcam footage, application packages, and firmware files are exposed to anyone on the internet.