Skip to main content

VU#234131: ViewSonic vCast media streaming service allows unauthenticated screen exfiltration and device compromise

0
Critical
VulnerabilityCVE-2026-82989androidremote
Published: 09/24/2026 (09/24/2026, 19:27:42 UTC)
Source: CERT/CC

Description

ViewSonic vCast software, used in ViewBoard smartboards, contains multiple unauthenticated vulnerabilities that can be chained by a remote attacker to fully compromise the device. These include screen content exfiltration via unauthenticated API endpoints, unprivileged APK installation through an unauthenticated download endpoint, and arbitrary input injection via exposed network services. Exploitation requires network access but no user interaction. No vendor fix is currently available, and network segmentation and monitoring are recommended as interim mitigations.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/24/2026, 19:30:45 UTC

Technical Analysis

The ViewSonic vCast media streaming service, part of the ViewBoard smartboard devices running Android, has three distinct vulnerabilities exploitable without authentication. CVE-2026-82989 allows remote exfiltration of JPEG images of the screen via unauthenticated GET requests to /snapshot or /screen endpoints. CVE-2026-82988 permits remote triggering of unprivileged APK installation by supplying a malicious APK URL to an unauthenticated download endpoint. CVE-2026-82987 enables remote injection of arbitrary input into service endpoints through HTTP requests to exposed unauthenticated network services. These vulnerabilities can be chained by an attacker on the same network to execute arbitrary code and fully compromise the device, including persistent malicious app installation and unauthorized access to displayed content. The vendor has not responded to coordination requests, and no official patch or fix is currently available.

Potential Impact

An unauthenticated remote attacker on the same network can exploit these vulnerabilities to exfiltrate screen content, install arbitrary applications without privileges, and execute arbitrary code on the device. This leads to full device compromise, unauthorized access to sensitive displayed information, persistent malware installation, and potential lateral movement within the connected network environment.

Mitigation Recommendations

No official patch or fix is currently available as the vendor has not responded to coordination efforts. Interim mitigations include applying firmware updates when they become available, segmenting vCast devices onto isolated and secure networks with strict access controls separate from sensitive systems, and monitoring network activity for suspicious vCast-related connections.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.65,"severitySource":"default","classifier":"rss-v2"}
Article Source
{"url":"https://kb.cert.org/vuls/id/234131","fetched":true,"fetchedAt":"2026-09-24T19:30:41.707Z","wordCount":479}

Threat ID: 6ab57a61f7a7c54106bea1d4

Added to database: 09/24/2026, 19:30:41 UTC

Last enriched: 09/24/2026, 19:30:45 UTC

Last updated: 09/25/2026, 05:17:10 UTC

Views: 27

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses