{"id":"CVE-2026-94204","title":"The central cloud storage backend for the entire dashcam platform is misconfigured with public-read permissions, allowing unrestricted access to all stored objects","summary":"The central cloud storage backend for the entire dashcam platform is misconfigured with public-read permissions, allowing unrestricted access to all stored objects. Because this bucket serves as shared storage for the platform, sensitive…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-732"],"vendor":"Viidure","product":"Dashcam Android Application","affected":["dashcam_android_application <= 3.3.1.260403"],"published":"2026-09-29","updated":"2026-09-29","sourceUpdated":"2026-09-29T22:19:03.923","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-94204","references":[{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-272-07.json","label":"ics-cert@hq.dhs.gov"},{"url":"https://viidure.app/","label":"ics-cert@hq.dhs.gov"},{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-07","label":"ics-cert@hq.dhs.gov"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"partial","timestamp":"2026-09-29T20:55:08.569132Z"},"ingestedAt":"2026-09-29T21:49:08.218Z","slug":"CVE-2026-94204","body":"## Overview\n\nThe central cloud storage backend for the entire dashcam platform is misconfigured with public-read permissions, allowing unrestricted access to all stored objects. Because this bucket serves as shared storage for the platform, sensitive user records, live dashcam footage, application packages, and firmware files are exposed to anyone on the internet.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}