AI analysis
The Viidure Android companion app for Viidure dashcams permanently embeds plaintext cloud storage credentials in its compiled code (CWE-798). Anyone who obtains the publicly downloadable APK can decompile it and extract those credentials with no privileges, no user interaction, and no attack prerequisites, then use them over the network. Armed with the credentials, an attacker gains full read, write, and delete access to the platform's cloud storage — including firmware images and application binaries — enabling theft or destruction of stored content and, in the worst case, tampering with firmware/app files in a fleet-wide supply-chain compromise, which is why the flaw is rated CVSS 4.0 critical (10.0). Because the credential is shared and permanent, a single extraction exposes every user of the platform, not just the individual holding the phone. No public proof of concept is known, the flaw is not on CISA's KEV list, and no exploitation in the wild has been reported to date.
What to do: Viidure must immediately revoke and rotate the embedded cloud credentials, purge all secrets from app source code, and replace them with per-user, short-lived tokens, while auditing storage access logs for unauthorized use — the credentials have been exposed for the lifetime of every shipped app build. The vendor should also verify the integrity of stored firmware and application binaries against tampering, since attackers could have planted malicious updates. Users should install the fixed app and any resulting firmware updates as soon as they are released, and review their cloud-stored footage and devices for signs of deletion or modification.
Affected
| Viidure Android application (dashcam companion app) | — |
Estimated exposure
moderateTens of thousands of users/dashcams (order-of-magnitude estimate; no official install counts published) — Viidure is a mid-tier consumer dashcam brand whose Android companion apps typically accumulate tens of thousands of downloads, and because a single hardcoded credential guards the shared cloud backend, the potential blast radius spans the…
Description
The Viidure Android application embeds permanent, plaintext cloud storage credentials within its compiled code. These credentials provide full access to critical platform storage, including the ability to read, modify, or delete operational files such as firmware and application binaries.