Machine-generated analysis · WAYSCloud LLM
The advisory reports that the dashcam platform’s cloud storage bucket is publicly readable, exposing user data and firmware.
Context
The affected product is the Viidure Dashcam Android Application version 3.3.1.260403 and earlier. The advisory states that the central cloud storage backend is misconfigured with public-read permissions, allowing unrestricted access to stored objects. It also notes that the application embeds permanent, plaintext cloud storage credentials. Viidure has not provided a fix and did not respond to coordination attempts.
Operator considerations
Check: Inventory devices running Viidure Dashcam Android Application version 3.3.1.260403 or earlier.
Isolate: Restrict network traffic from the application to the cloud storage endpoint until the issue is mitigated.
Log: Monitor access logs for the cloud storage bucket for unexpected external requests.
Successful exploitation of these vulnerabilities could allow attackers to access, modify, or delete sensitive user data and critical system files, potentially compromising the operation of the entire platform.
The following versions of Viidure Dashcam Android Application are affected:
Dashcam Android Application
Read the full advisory on CISA →