HackerFeeds
All CVEs

CVE-2026-96587

CRITICAL10.0

Published 2026-09-29 · Updated 2026-09-29 · Source ics-cert@hq.dhs.gov

Description

The Viidure Android application embeds permanent, plaintext cloud storage credentials within its compiled code. These credentials provide full access to critical platform storage, including the ability to read, modify, or delete operational files such as firmware and application binaries.

CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CWE-798
View on NVD